Логотип exploitDog
bind:"CVE-2023-37329"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2023-37329"

Количество 14

Количество 14

ubuntu логотип

CVE-2023-37329

больше 1 года назад

GStreamer SRT File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the parsing of SRT subtitle files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-20968.

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2023-37329

больше 2 лет назад

GStreamer SRT File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the parsing of SRT subtitle files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-20968.

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2023-37329

больше 1 года назад

GStreamer SRT File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the parsing of SRT subtitle files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-20968.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2023-37329

больше 1 года назад

GStreamer SRT File Parsing Heap-based Buffer Overflow Remote Code Exec ...

CVSS3: 8.8
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2023:0379-1

около 2 лет назад

Security update for gstreamer-plugins-bad

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:3802-1

около 2 лет назад

Security update for gstreamer-plugins-bad

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:3267-1

больше 2 лет назад

Security update for gstreamer-plugins-bad

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:3249-1

больше 2 лет назад

Security update for gstreamer-plugins-bad

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:3235-1

больше 2 лет назад

Security update for gstreamer-plugins-bad

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:3220-1

больше 2 лет назад

Security update for gstreamer-plugins-bad

EPSS: Низкий
github логотип

GHSA-6jh6-8262-gqc4

больше 1 года назад

GStreamer SRT File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the parsing of SRT subtitle files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-20968.

CVSS3: 8.8
EPSS: Низкий
fstec логотип

BDU:2023-04340

больше 2 лет назад

Уязвимость плагина Base (gst-plugins-base) мультимедийного фреймворка Gstreamer, позволяющая нарушителю выполнить произвольный код

CVSS3: 8.8
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:4971-1

почти 2 года назад

Security update for gstreamer-plugins-bad

EPSS: Низкий
redos логотип

ROS-20230915-11

около 2 лет назад

Уязвимость GStreamer

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2023-37329

GStreamer SRT File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the parsing of SRT subtitle files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-20968.

CVSS3: 8.8
5%
Низкий
больше 1 года назад
redhat логотип
CVE-2023-37329

GStreamer SRT File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the parsing of SRT subtitle files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-20968.

CVSS3: 5.5
5%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-37329

GStreamer SRT File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the parsing of SRT subtitle files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-20968.

CVSS3: 8.8
5%
Низкий
больше 1 года назад
debian логотип
CVE-2023-37329

GStreamer SRT File Parsing Heap-based Buffer Overflow Remote Code Exec ...

CVSS3: 8.8
5%
Низкий
больше 1 года назад
suse-cvrf логотип
openSUSE-SU-2023:0379-1

Security update for gstreamer-plugins-bad

5%
Низкий
около 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:3802-1

Security update for gstreamer-plugins-bad

5%
Низкий
около 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:3267-1

Security update for gstreamer-plugins-bad

5%
Низкий
больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:3249-1

Security update for gstreamer-plugins-bad

5%
Низкий
больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:3235-1

Security update for gstreamer-plugins-bad

5%
Низкий
больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:3220-1

Security update for gstreamer-plugins-bad

5%
Низкий
больше 2 лет назад
github логотип
GHSA-6jh6-8262-gqc4

GStreamer SRT File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the parsing of SRT subtitle files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-20968.

CVSS3: 8.8
5%
Низкий
больше 1 года назад
fstec логотип
BDU:2023-04340

Уязвимость плагина Base (gst-plugins-base) мультимедийного фреймворка Gstreamer, позволяющая нарушителю выполнить произвольный код

CVSS3: 8.8
5%
Низкий
больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:4971-1

Security update for gstreamer-plugins-bad

почти 2 года назад
redos логотип
ROS-20230915-11

Уязвимость GStreamer

CVSS3: 8.8
5%
Низкий
около 2 лет назад

Уязвимостей на страницу