CVE-2017-5845
- EPSS 3.11%
- Veröffentlicht 09.02.2017 15:59:01
- Zuletzt bearbeitet 13.05.2026 00:24:29
The gst_avi_demux_parse_ncdt function in gst/avi/gstavidemux.c in gst-plugins-good in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (invalid memory read and crash) via a ncdt sub-tag that "goes behind" the surrounding t...
CVE-2017-5846
- EPSS 0.8%
- Veröffentlicht 09.02.2017 15:59:01
- Zuletzt bearbeitet 13.05.2026 00:24:29
The gst_asf_demux_process_ext_stream_props function in gst/asfdemux/gstasfdemux.c in gst-plugins-ugly in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (invalid memory read and crash) via vectors related to the number of...
CVE-2017-5847
- EPSS 3.07%
- Veröffentlicht 09.02.2017 15:59:01
- Zuletzt bearbeitet 13.05.2026 00:24:29
The gst_asf_demux_process_ext_content_desc function in gst/asfdemux/gstasfdemux.c in gst-plugins-ugly in GStreamer allows remote attackers to cause a denial of service (out-of-bounds heap read) via vectors involving extended content descriptors.
CVE-2017-5848
- EPSS 6.52%
- Veröffentlicht 09.02.2017 15:59:01
- Zuletzt bearbeitet 13.05.2026 00:24:29
The gst_ps_demux_parse_psm function in gst/mpegdemux/gstmpegdemux.c in gst-plugins-bad in GStreamer allows remote attackers to cause a denial of service (invalid memory read and crash) via vectors involving PSM parsing.
CVE-2016-10198
- EPSS 1.67%
- Veröffentlicht 09.02.2017 15:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The gst_aac_parse_sink_setcaps function in gst/audioparsers/gstaacparse.c in gst-plugins-good in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (invalid memory read and crash) via a crafted audio file.
CVE-2016-10199
- EPSS 3.13%
- Veröffentlicht 09.02.2017 15:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The qtdemux_tag_add_str_full function in gst/isomp4/qtdemux.c in gst-plugins-good in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted tag value.
CVE-2016-9636
- EPSS 16.64%
- Veröffentlicht 27.01.2017 22:59:02
- Zuletzt bearbeitet 13.05.2026 00:24:29
Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstflxdec.c in the FLIC decoder in GStreamer before 1.10.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) by providing a 'w...
CVE-2016-9634
- EPSS 16.09%
- Veröffentlicht 27.01.2017 22:59:01
- Zuletzt bearbeitet 13.05.2026 00:24:29
Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstflxdec.c in the FLIC decoder in GStreamer before 1.10.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via the start_lin...
CVE-2016-9635
- EPSS 16.09%
- Veröffentlicht 27.01.2017 22:59:01
- Zuletzt bearbeitet 13.05.2026 00:24:29
Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstflxdec.c in the FLIC decoder in GStreamer before 1.10.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) by providing a 's...
CVE-2016-9445
- EPSS 5.95%
- Veröffentlicht 23.01.2017 21:59:03
- Zuletzt bearbeitet 13.05.2026 00:24:29
Integer overflow in the vmnc decoder in the gstreamer allows remote attackers to cause a denial of service (crash) via large width and height values, which triggers a buffer overflow.