CVE-2016-1897

MEDIUM

FFmpeg 2.x - XSS

Title source: llm

Description

FFmpeg 2.x allows remote attackers to conduct cross-origin attacks and read arbitrary files by using the concat protocol in an HTTP Live Streaming (HLS) M3U8 file, leading to an external HTTP request in which the URL string contains the first line of a local file.

Scores

CVSS v3 5.5
EPSS 0.5776
EPSS Percentile 98.1%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Classification

CWE
CWE-200
Status draft

Affected Products (50)

ffmpeg/ffmpeg
ffmpeg/ffmpeg
ffmpeg/ffmpeg
ffmpeg/ffmpeg
ffmpeg/ffmpeg
ffmpeg/ffmpeg
ffmpeg/ffmpeg
ffmpeg/ffmpeg
ffmpeg/ffmpeg
ffmpeg/ffmpeg
ffmpeg/ffmpeg
ffmpeg/ffmpeg
ffmpeg/ffmpeg
ffmpeg/ffmpeg
ffmpeg/ffmpeg
... and 35 more

Timeline

Published Jan 15, 2016
Tracked Since Feb 18, 2026