CVE-2016-9634
- EPSS 16.09%
- Published 27.01.2017 22:59:01
- Last modified 20.04.2025 01:37:25
Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstflxdec.c in the FLIC decoder in GStreamer before 1.10.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via the start_lin...
CVE-2016-9813
- EPSS 5.4%
- Published 13.01.2017 16:59:01
- Last modified 20.04.2025 01:37:25
The _parse_pat function in the mpegts parser in GStreamer before 1.10.2 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted file.
CVE-2016-9812
- EPSS 1.41%
- Published 13.01.2017 16:59:01
- Last modified 20.04.2025 01:37:25
The gst_mpegts_section_new function in the mpegts decoder in GStreamer before 1.10.2 allows remote attackers to cause a denial of service (out-of-bounds read) via a too small section.
CVE-2016-9811
- EPSS 0.49%
- Published 13.01.2017 16:59:01
- Last modified 20.04.2025 01:37:25
The windows_icon_typefind function in gst-plugins-base in GStreamer before 1.10.2, when G_SLICE is set to always-malloc, allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted ico file.
CVE-2016-9810
- EPSS 0.67%
- Published 13.01.2017 16:59:01
- Last modified 20.04.2025 01:37:25
The gst_decode_chain_free_internal function in the flxdex decoder in gst-plugins-good in GStreamer before 1.10.2 allows remote attackers to cause a denial of service (invalid memory read and crash) via an invalid file, which triggers an incorrect unr...
CVE-2016-9809
- EPSS 0.47%
- Published 13.01.2017 16:59:01
- Last modified 20.04.2025 01:37:25
Off-by-one error in the gst_h264_parse_set_caps function in GStreamer before 1.10.2 allows remote attackers to have unspecified impact via a crafted file, which triggers an out-of-bounds read.
CVE-2016-9808
- EPSS 7.19%
- Published 13.01.2017 16:59:01
- Last modified 20.04.2025 01:37:25
The FLIC decoder in GStreamer before 1.10.2 allows remote attackers to cause a denial of service (out-of-bounds write and crash) via a crafted series of skip and count pairs.
CVE-2016-9807
- EPSS 0.77%
- Published 13.01.2017 16:59:00
- Last modified 20.04.2025 01:37:25
The flx_decode_chunks function in gst/flx/gstflxdec.c in GStreamer before 1.10.2 allows remote attackers to cause a denial of service (invalid memory read and crash) via a crafted FLIC file.