6.8

CVE-2015-0797

GStreamer before 1.4.5, as used in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 on Linux, allows remote attackers to cause a denial of service (buffer over-read and application crash) or possibly execute arbitrary code via crafted H.264 video data in an m4v file.

Data is provided by the National Vulnerability Database (NVD)
Gstreamer ProjectGstreamer Version < 1.4.5
   LinuxLinux Kernel Version-
MozillaFirefox Version < 38.0
   LinuxLinux Kernel Version-
MozillaFirefox Version >= 31.0 < 31.7
   LinuxLinux Kernel Version-
MozillaSeamonkey Version < 2.35
   LinuxLinux Kernel Version-
MozillaThunderbird Version < 31.7
   LinuxLinux Kernel Version-
MozillaThunderbird Version >= 38.0 < 38.0.1
   LinuxLinux Kernel Version-
SuseLinux Enterprise Desktop Version11 Updatesp3
SuseLinux Enterprise Server Version11 Updatesp3 SwPlatform-
SuseLinux Enterprise Server Version11 Updatesp3 SwPlatformvmware
RedhatEnterprise Linux Eus Version6.6
RedhatEnterprise Linux Eus Version7.1
RedhatEnterprise Linux Eus Version7.2
RedhatEnterprise Linux Eus Version7.3
RedhatEnterprise Linux Eus Version7.4
RedhatEnterprise Linux Eus Version7.5
RedhatEnterprise Linux Eus Version7.6
RedhatEnterprise Linux Eus Version7.7
DebianDebian Linux Version7.0
DebianDebian Linux Version8.0
DebianDebian Linux Version9.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 7.61% 0.914
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P