Vulnerabilities
Vulnerable Software
Gstreamer Project:  >> Gstreamer  Security Vulnerabilities
GStreamer before 1.18.4 might access already-freed memory in error code paths when demuxing certain malformed Matroska files.
CVSS Score
7.8
EPSS Score
0.002
Published
2021-04-19
GStreamer before 1.18.4 might cause heap corruption when parsing certain malformed Matroska files.
CVSS Score
7.8
EPSS Score
0.003
Published
2021-04-19
GStreamer before 1.16.0 has a heap-based buffer overflow in the RTSP connection parser via a crafted response from a server, potentially allowing remote code execution.
CVSS Score
8.8
EPSS Score
0.164
Published
2019-04-24
The gst_riff_create_audio_caps function in gst-libs/gst/riff/riff-media.c in gst-plugins-base in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (floating point exception and crash) via a crafted video file.
CVSS Score
5.5
EPSS Score
0.008
Published
2017-02-09
The gst_date_time_new_from_iso8601_string function in gst/gstdatetime.c in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a malformed datetime string.
CVSS Score
7.5
EPSS Score
0.028
Published
2017-02-09
The gst_riff_create_audio_caps function in gst-libs/gst/riff/riff-media.c in gst-plugins-base in GStreamer before 1.10.3 does not properly limit recursion, which allows remote attackers to cause a denial of service (stack overflow and crash) via vectors involving nested WAVEFORMATEX.
CVSS Score
7.5
EPSS Score
0.024
Published
2017-02-09
The qtdemux_parse_samples function in gst/isomp4/qtdemux.c in gst-plugins-good in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (out-of-bounds heap read) via vectors involving the current stts index.
CVSS Score
7.5
EPSS Score
0.141
Published
2017-02-09
The gst_avi_demux_parse_ncdt function in gst/avi/gstavidemux.c in gst-plugins-good in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (out-of-bounds heap read) via vectors involving ncdt tags.
CVSS Score
7.5
EPSS Score
0.025
Published
2017-02-09
The html_context_handle_element function in gst/subparse/samiparse.c in gst-plugins-base in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted SMI file, as demonstrated by OneNote_Manager.smi.
CVSS Score
5.5
EPSS Score
0.008
Published
2017-02-09
Multiple use-after-free vulnerabilities in the (1) gst_mini_object_unref, (2) gst_tag_list_unref, and (3) gst_mxf_demux_update_essence_tracks functions in GStreamer before 1.10.3 allow remote attackers to cause a denial of service (crash) via vectors involving stream tags, as demonstrated by 02785736.mxf.
CVSS Score
7.5
EPSS Score
0.066
Published
2017-02-09


Contact Us

Shodan ® - All rights reserved