Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 19

Количество 19

oracle-oval логотип

ELSA-2026-69100

2 дня назад

ELSA-2026-69100: gstreamer1-plugins-base security update (IMPORTANT)

EPSS: Низкий
ubuntu логотип

CVE-2026-85150

20 дней назад

A NULL pointer dereference flaw was found in GStreamer's RTSP support library. The vulnerability occurs while parsing an Authorization or WWW-Authenticate header that uses Digest authentication. Specially crafted whitespace placement around a parameter's terminator can cause an internal length calculation to underflow, leading to a crash of the process parsing the header. On an RTSP server this can be triggered by a remote, unauthenticated attacker sending a single malformed request when the server has authentication enabled; the same flaw can also be triggered against an RTSP client by a malicious or compromised RTSP server. Successful exploitation results in a denial of service (application crash) and has no confirmed impact on confidentiality or integrity.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-85150

20 дней назад

A NULL pointer dereference flaw was found in GStreamer's RTSP support library. The vulnerability occurs while parsing an Authorization or WWW-Authenticate header that uses Digest authentication. Specially crafted whitespace placement around a parameter's terminator can cause an internal length calculation to underflow, leading to a crash of the process parsing the header. On an RTSP server this can be triggered by a remote, unauthenticated attacker sending a single malformed request when the server has authentication enabled; the same flaw can also be triggered against an RTSP client by a malicious or compromised RTSP server. Successful exploitation results in a denial of service (application crash) and has no confirmed impact on confidentiality or integrity.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-85150

20 дней назад

A NULL pointer dereference flaw was found in GStreamer's RTSP support library. The vulnerability occurs while parsing an Authorization or WWW-Authenticate header that uses Digest authentication. Specially crafted whitespace placement around a parameter's terminator can cause an internal length calculation to underflow, leading to a crash of the process parsing the header. On an RTSP server this can be triggered by a remote, unauthenticated attacker sending a single malformed request when the server has authentication enabled; the same flaw can also be triggered against an RTSP client by a malicious or compromised RTSP server. Successful exploitation results in a denial of service (application crash) and has no confirmed impact on confidentiality or integrity.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2026-85150

20 дней назад

A NULL pointer dereference flaw was found in GStreamer's RTSP support ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2026-18297

около 1 месяца назад

GStreamer OGG File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of OGG files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29584.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2026-18297

около 1 месяца назад

GStreamer OGG File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of OGG files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29584.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-18297

около 1 месяца назад

GStreamer OGG File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of OGG files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29584.

CVSS3: 7.8
EPSS: Низкий
debian логотип

CVE-2026-18297

около 1 месяца назад

GStreamer OGG File Parsing Stack-based Buffer Overflow Remote Code Exe ...

CVSS3: 7.8
EPSS: Низкий
rocky логотип

RLSA-2026:67145

8 дней назад

Moderate: gstreamer1-plugins-base security update

EPSS: Низкий
rocky логотип

RLSA-2026:66460

12 дней назад

Moderate: gstreamer1-plugins-base security update

EPSS: Низкий
rocky логотип

RLSA-2026:59487

28 дней назад

Important: gstreamer1-plugins-base security update

EPSS: Низкий
rocky логотип

RLSA-2026:59097

29 дней назад

Important: gstreamer1-plugins-base security update

EPSS: Низкий
github логотип

GHSA-q4wf-cmpg-8rhf

20 дней назад

A NULL pointer dereference flaw was found in GStreamer's RTSP support library. The vulnerability occurs while parsing an Authorization or WWW-Authenticate header that uses Digest authentication. Specially crafted whitespace placement around a parameter's terminator can cause an internal length calculation to underflow, leading to a crash of the process parsing the header. On an RTSP server this can be triggered by a remote, unauthenticated attacker sending a single malformed request when the server has authentication enabled; the same flaw can also be triggered against an RTSP client by a malicious or compromised RTSP server. Successful exploitation results in a denial of service (application crash) and has no confirmed impact on confidentiality or integrity.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-gqxr-5q6c-5cqh

около 1 месяца назад

GStreamer OGG File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of OGG files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29584.

CVSS3: 7.8
EPSS: Низкий
oracle-oval логотип

ELSA-2026-67145-0

9 дней назад

ELSA-2026-67145-0: gstreamer1-plugins-base security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-66460-0

12 дней назад

ELSA-2026-66460-0: gstreamer1-plugins-base security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-59487

29 дней назад

ELSA-2026-59487: gstreamer1-plugins-base security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-59097

около 1 месяца назад

ELSA-2026-59097: gstreamer1-plugins-base security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
oracle-oval логотип
ELSA-2026-69100

ELSA-2026-69100: gstreamer1-plugins-base security update (IMPORTANT)

2 дня назад
ubuntu логотип
CVE-2026-85150

A NULL pointer dereference flaw was found in GStreamer's RTSP support library. The vulnerability occurs while parsing an Authorization or WWW-Authenticate header that uses Digest authentication. Specially crafted whitespace placement around a parameter's terminator can cause an internal length calculation to underflow, leading to a crash of the process parsing the header. On an RTSP server this can be triggered by a remote, unauthenticated attacker sending a single malformed request when the server has authentication enabled; the same flaw can also be triggered against an RTSP client by a malicious or compromised RTSP server. Successful exploitation results in a denial of service (application crash) and has no confirmed impact on confidentiality or integrity.

CVSS3: 7.5
1%
Низкий
20 дней назад
redhat логотип
CVE-2026-85150

A NULL pointer dereference flaw was found in GStreamer's RTSP support library. The vulnerability occurs while parsing an Authorization or WWW-Authenticate header that uses Digest authentication. Specially crafted whitespace placement around a parameter's terminator can cause an internal length calculation to underflow, leading to a crash of the process parsing the header. On an RTSP server this can be triggered by a remote, unauthenticated attacker sending a single malformed request when the server has authentication enabled; the same flaw can also be triggered against an RTSP client by a malicious or compromised RTSP server. Successful exploitation results in a denial of service (application crash) and has no confirmed impact on confidentiality or integrity.

CVSS3: 7.5
1%
Низкий
20 дней назад
nvd логотип
CVE-2026-85150

A NULL pointer dereference flaw was found in GStreamer's RTSP support library. The vulnerability occurs while parsing an Authorization or WWW-Authenticate header that uses Digest authentication. Specially crafted whitespace placement around a parameter's terminator can cause an internal length calculation to underflow, leading to a crash of the process parsing the header. On an RTSP server this can be triggered by a remote, unauthenticated attacker sending a single malformed request when the server has authentication enabled; the same flaw can also be triggered against an RTSP client by a malicious or compromised RTSP server. Successful exploitation results in a denial of service (application crash) and has no confirmed impact on confidentiality or integrity.

CVSS3: 7.5
1%
Низкий
20 дней назад
debian логотип
CVE-2026-85150

A NULL pointer dereference flaw was found in GStreamer's RTSP support ...

CVSS3: 7.5
1%
Низкий
20 дней назад
ubuntu логотип
CVE-2026-18297

GStreamer OGG File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of OGG files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29584.

CVSS3: 7.8
0%
Низкий
около 1 месяца назад
redhat логотип
CVE-2026-18297

GStreamer OGG File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of OGG files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29584.

CVSS3: 7.8
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-18297

GStreamer OGG File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of OGG files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29584.

CVSS3: 7.8
0%
Низкий
около 1 месяца назад
debian логотип
CVE-2026-18297

GStreamer OGG File Parsing Stack-based Buffer Overflow Remote Code Exe ...

CVSS3: 7.8
0%
Низкий
около 1 месяца назад
rocky логотип
RLSA-2026:67145

Moderate: gstreamer1-plugins-base security update

1%
Низкий
8 дней назад
rocky логотип
RLSA-2026:66460

Moderate: gstreamer1-plugins-base security update

1%
Низкий
12 дней назад
rocky логотип
RLSA-2026:59487

Important: gstreamer1-plugins-base security update

0%
Низкий
28 дней назад
rocky логотип
RLSA-2026:59097

Important: gstreamer1-plugins-base security update

0%
Низкий
29 дней назад
github логотип
GHSA-q4wf-cmpg-8rhf

A NULL pointer dereference flaw was found in GStreamer's RTSP support library. The vulnerability occurs while parsing an Authorization or WWW-Authenticate header that uses Digest authentication. Specially crafted whitespace placement around a parameter's terminator can cause an internal length calculation to underflow, leading to a crash of the process parsing the header. On an RTSP server this can be triggered by a remote, unauthenticated attacker sending a single malformed request when the server has authentication enabled; the same flaw can also be triggered against an RTSP client by a malicious or compromised RTSP server. Successful exploitation results in a denial of service (application crash) and has no confirmed impact on confidentiality or integrity.

CVSS3: 7.5
1%
Низкий
20 дней назад
github логотип
GHSA-gqxr-5q6c-5cqh

GStreamer OGG File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of OGG files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29584.

CVSS3: 7.8
0%
Низкий
около 1 месяца назад
oracle-oval логотип
ELSA-2026-67145-0

ELSA-2026-67145-0: gstreamer1-plugins-base security update (MODERATE)

1%
Низкий
9 дней назад
oracle-oval логотип
ELSA-2026-66460-0

ELSA-2026-66460-0: gstreamer1-plugins-base security update (MODERATE)

1%
Низкий
12 дней назад
oracle-oval логотип
ELSA-2026-59487

ELSA-2026-59487: gstreamer1-plugins-base security update (IMPORTANT)

0%
Низкий
29 дней назад
oracle-oval логотип
ELSA-2026-59097

ELSA-2026-59097: gstreamer1-plugins-base security update (IMPORTANT)

0%
Низкий
около 1 месяца назад

Уязвимостей на страницу