Gstreamer Project

Gstreamer

80 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.83%
  • Veröffentlicht 09.02.2017 15:59:01
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The gst_asf_demux_process_ext_stream_props function in gst/asfdemux/gstasfdemux.c in gst-plugins-ugly in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (invalid memory read and crash) via vectors related to the number of...

  • EPSS 3.09%
  • Veröffentlicht 09.02.2017 15:59:01
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The gst_asf_demux_process_ext_content_desc function in gst/asfdemux/gstasfdemux.c in gst-plugins-ugly in GStreamer allows remote attackers to cause a denial of service (out-of-bounds heap read) via vectors involving extended content descriptors.

  • EPSS 5.48%
  • Veröffentlicht 09.02.2017 15:59:01
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The gst_ps_demux_parse_psm function in gst/mpegdemux/gstmpegdemux.c in gst-plugins-bad in GStreamer allows remote attackers to cause a denial of service (invalid memory read and crash) via vectors involving PSM parsing.

  • EPSS 5.18%
  • Veröffentlicht 09.02.2017 15:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The qtdemux_tag_add_str_full function in gst/isomp4/qtdemux.c in gst-plugins-good in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted tag value.

  • EPSS 2.17%
  • Veröffentlicht 09.02.2017 15:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The gst_aac_parse_sink_setcaps function in gst/audioparsers/gstaacparse.c in gst-plugins-good in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (invalid memory read and crash) via a crafted audio file.

  • EPSS 0.48%
  • Veröffentlicht 23.01.2017 21:59:03
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The ROM mappings in the NSF decoder in gstreamer 0.10.x allow remote attackers to cause a denial of service (out-of-bounds read or write) and possibly execute arbitrary code via a crafted NSF music file.

  • EPSS 1.28%
  • Veröffentlicht 23.01.2017 21:59:03
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The vmnc decoder in the gstreamer does not initialize the render canvas, which allows remote attackers to obtain sensitive information as demonstrated by thumbnailing a simple 1 frame vmnc movie that does not draw to the allocated render canvas.

  • EPSS 2.41%
  • Veröffentlicht 23.01.2017 21:59:03
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Integer overflow in the vmnc decoder in the gstreamer allows remote attackers to cause a denial of service (crash) via large width and height values, which triggers a buffer overflow.

  • EPSS 7.61%
  • Veröffentlicht 14.05.2015 10:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

GStreamer before 1.4.5, as used in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 on Linux, allows remote attackers to cause a denial of service (buffer over-read and application crash) or possibly execute arbi...

  • EPSS 3.15%
  • Veröffentlicht 14.03.2009 18:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Integer overflow in the gst_vorbis_tag_add_coverart function (gst-libs/gst/tag/gstvorbistag.c) in vorbistag in gst-plugins-base (aka gstreamer-plugins-base) before 0.10.23 in GStreamer allows context-dependent attackers to execute arbitrary code via ...