Is FFmpeg 3.3.9 patched?
Current stable (8.1.1): 94/100
Summary iPlain-English security status for FFmpeg 3.3.9, built from its CVEs, active-exploitation data, end-of-life date and latest release.
FFmpeg 3.3.9 is part of the 3.3 release line. 38 known vulnerabilities affect it. The 3.3 line reached end-of-life on 2018-11-18, so it no longer receives security patches. The latest supported FFmpeg release is 8.1.1.
Known issues affecting 3.3.9
Exploited first, then by exploitation probability.
CVE-2018-1999011 HIGH EPSS 4% → see advisory CVE-2018-1999010 CRITICAL EPSS 3% → fixed in 3.4.3 CVE-2021-38291 HIGH EPSS 3% → fixed in 4.4.1 CVE-2018-10001 MEDIUM EPSS 2% → see advisory CVE-2018-7751 MEDIUM EPSS 2% → see advisory CVE-2018-1999012 MEDIUM EPSS 2% → see advisory CVE-2019-15942 HIGH EPSS 2% → see advisory CVE-2019-17539 CRITICAL EPSS 2% → fixed in 4.1.5 CVE-2018-7557 MEDIUM EPSS 2% → see advisory CVE-2018-1999013 MEDIUM EPSS 2% → see advisory CVE-2018-9841 HIGH EPSS 2% → see advisory CVE-2018-1999015 MEDIUM EPSS 2% → see advisory CVE-2018-6392 MEDIUM EPSS 2% → see advisory CVE-2022-48434 HIGH EPSS 2% → fixed in 5.1.2 CVE-2018-6912 MEDIUM EPSS 1% → see advisory CVE-2018-1999014 MEDIUM EPSS 1% → see advisory CVE-2022-3109 HIGH EPSS 1% → fixed in 5.0.3 CVE-2024-7272 MEDIUM EPSS 1% → fixed in 5.1.6 CVE-2018-14394 MEDIUM EPSS 1% → fixed in 4.0.2 CVE-2024-7055 MEDIUM EPSS 1% → fixed in 7.0.2Other FFmpeg versions
Check another release line of FFmpeg.
Frequently asked
Is FFmpeg 3.3.9 patched?
FFmpeg 3.3.9 is end-of-life and no longer receives security patches. Move to 8.1.1.
When does FFmpeg 3.3 reach end-of-life?
FFmpeg 3.3 reached end-of-life on 2018-11-18 and no longer receives security patches.
What is the latest version of FFmpeg?
The latest supported FFmpeg release is 8.1.1.
Is FFmpeg 3.3.9 still receiving security updates?
No — FFmpeg 3.3.9 is on the 3.3 line, which reached end-of-life on 2018-11-18 and no longer receives security updates. Upgrade to 8.1.1 or later to stay supported.
Informational only, from public data (NVD · CISA KEV · EPSS · endoflife.date), and can lag or miss vendor-specific fixes. Always confirm against FFmpeg's official advisory before you patch or upgrade — FFmpeg official site ↗