Количество 17
Количество 17
ELSA-2026-47180
ELSA-2026-47180: gstreamer1-plugins-bad-free security update (IMPORTANT)
ELSA-2026-47179
ELSA-2026-47179: gstreamer1-plugins-bad-free security update (IMPORTANT)
CVE-2026-59691
A heap buffer overflow vulnerability was found in GStreamer's rfbsrc plugin. When a client connects to a malicious RFB/VNC server that advertises a 16bpp framebuffer and sends Hextile-encoded updates, the Hextile background fill path writes 32-bit pixel values into a buffer allocated for 16-bit pixels. This type mismatch causes an out-of-bounds heap write that can lead to denial of service (process crash) and potential memory corruption.
CVE-2026-59691
A heap buffer overflow vulnerability was found in GStreamer's rfbsrc plugin. When a client connects to a malicious RFB/VNC server that advertises a 16bpp framebuffer and sends Hextile-encoded updates, the Hextile background fill path writes 32-bit pixel values into a buffer allocated for 16-bit pixels. This type mismatch causes an out-of-bounds heap write that can lead to denial of service (process crash) and potential memory corruption.
CVE-2026-59691
A heap buffer overflow vulnerability was found in GStreamer's rfbsrc plugin. When a client connects to a malicious RFB/VNC server that advertises a 16bpp framebuffer and sends Hextile-encoded updates, the Hextile background fill path writes 32-bit pixel values into a buffer allocated for 16-bit pixels. This type mismatch causes an out-of-bounds heap write that can lead to denial of service (process crash) and potential memory corruption.
CVE-2026-59691
A heap buffer overflow vulnerability was found in GStreamer's rfbsrc p ...
CVE-2026-59692
A stack buffer overflow vulnerability was found in GStreamer's DTLS plugin. During a DTLS handshake, the peer certificate Subject Distinguished Name is printed into a fixed-size 2048-byte stack buffer without bounds checking. A remote unauthenticated attacker can send a certificate with an oversized Subject DN that exceeds the buffer, causing a stack buffer overflow and process crash, resulting in denial of service.
CVE-2026-59692
A stack buffer overflow vulnerability was found in GStreamer's DTLS plugin. During a DTLS handshake, the peer certificate Subject Distinguished Name is printed into a fixed-size 2048-byte stack buffer without bounds checking. A remote unauthenticated attacker can send a certificate with an oversized Subject DN that exceeds the buffer, causing a stack buffer overflow and process crash, resulting in denial of service.
CVE-2026-59692
A stack buffer overflow vulnerability was found in GStreamer's DTLS plugin. During a DTLS handshake, the peer certificate Subject Distinguished Name is printed into a fixed-size 2048-byte stack buffer without bounds checking. A remote unauthenticated attacker can send a certificate with an oversized Subject DN that exceeds the buffer, causing a stack buffer overflow and process crash, resulting in denial of service.
CVE-2026-59692
A stack buffer overflow vulnerability was found in GStreamer's DTLS pl ...
GHSA-g4ff-54hw-hj6r
A heap buffer overflow vulnerability was found in GStreamer's rfbsrc plugin. When a client connects to a malicious RFB/VNC server that advertises a 16bpp framebuffer and sends Hextile-encoded updates, the Hextile background fill path writes 32-bit pixel values into a buffer allocated for 16-bit pixels. This type mismatch causes an out-of-bounds heap write that can lead to denial of service (process crash) and potential memory corruption.
GHSA-f48p-mg4r-fhww
A stack buffer overflow vulnerability was found in GStreamer's DTLS plugin. During a DTLS handshake, the peer certificate Subject Distinguished Name is printed into a fixed-size 2048-byte stack buffer without bounds checking. A remote unauthenticated attacker can send a certificate with an oversized Subject DN that exceeds the buffer, causing a stack buffer overflow and process crash, resulting in denial of service.
SUSE-SU-2026:3299-1
Security update for gstreamer-plugins-bad
SUSE-SU-2026:3133-1
Security update for gstreamer-plugins-bad
SUSE-SU-2026:3125-1
Security update for gstreamer-plugins-bad
SUSE-SU-2026:3058-1
Security update for gstreamer-plugins-bad
openSUSE-SU-2026:21370-1
Security update for gstreamer-plugins-bad
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
ELSA-2026-47180 ELSA-2026-47180: gstreamer1-plugins-bad-free security update (IMPORTANT) | 4 дня назад | |||
ELSA-2026-47179 ELSA-2026-47179: gstreamer1-plugins-bad-free security update (IMPORTANT) | 3 дня назад | |||
CVE-2026-59691 A heap buffer overflow vulnerability was found in GStreamer's rfbsrc plugin. When a client connects to a malicious RFB/VNC server that advertises a 16bpp framebuffer and sends Hextile-encoded updates, the Hextile background fill path writes 32-bit pixel values into a buffer allocated for 16-bit pixels. This type mismatch causes an out-of-bounds heap write that can lead to denial of service (process crash) and potential memory corruption. | CVSS3: 7.1 | 0% Низкий | 22 дня назад | |
CVE-2026-59691 A heap buffer overflow vulnerability was found in GStreamer's rfbsrc plugin. When a client connects to a malicious RFB/VNC server that advertises a 16bpp framebuffer and sends Hextile-encoded updates, the Hextile background fill path writes 32-bit pixel values into a buffer allocated for 16-bit pixels. This type mismatch causes an out-of-bounds heap write that can lead to denial of service (process crash) and potential memory corruption. | CVSS3: 7.1 | 0% Низкий | 24 дня назад | |
CVE-2026-59691 A heap buffer overflow vulnerability was found in GStreamer's rfbsrc plugin. When a client connects to a malicious RFB/VNC server that advertises a 16bpp framebuffer and sends Hextile-encoded updates, the Hextile background fill path writes 32-bit pixel values into a buffer allocated for 16-bit pixels. This type mismatch causes an out-of-bounds heap write that can lead to denial of service (process crash) and potential memory corruption. | CVSS3: 7.1 | 0% Низкий | 22 дня назад | |
CVE-2026-59691 A heap buffer overflow vulnerability was found in GStreamer's rfbsrc p ... | CVSS3: 7.1 | 0% Низкий | 22 дня назад | |
CVE-2026-59692 A stack buffer overflow vulnerability was found in GStreamer's DTLS plugin. During a DTLS handshake, the peer certificate Subject Distinguished Name is printed into a fixed-size 2048-byte stack buffer without bounds checking. A remote unauthenticated attacker can send a certificate with an oversized Subject DN that exceeds the buffer, causing a stack buffer overflow and process crash, resulting in denial of service. | CVSS3: 7.5 | 0% Низкий | 22 дня назад | |
CVE-2026-59692 A stack buffer overflow vulnerability was found in GStreamer's DTLS plugin. During a DTLS handshake, the peer certificate Subject Distinguished Name is printed into a fixed-size 2048-byte stack buffer without bounds checking. A remote unauthenticated attacker can send a certificate with an oversized Subject DN that exceeds the buffer, causing a stack buffer overflow and process crash, resulting in denial of service. | CVSS3: 7.5 | 0% Низкий | 24 дня назад | |
CVE-2026-59692 A stack buffer overflow vulnerability was found in GStreamer's DTLS plugin. During a DTLS handshake, the peer certificate Subject Distinguished Name is printed into a fixed-size 2048-byte stack buffer without bounds checking. A remote unauthenticated attacker can send a certificate with an oversized Subject DN that exceeds the buffer, causing a stack buffer overflow and process crash, resulting in denial of service. | CVSS3: 7.5 | 0% Низкий | 22 дня назад | |
CVE-2026-59692 A stack buffer overflow vulnerability was found in GStreamer's DTLS pl ... | CVSS3: 7.5 | 0% Низкий | 22 дня назад | |
GHSA-g4ff-54hw-hj6r A heap buffer overflow vulnerability was found in GStreamer's rfbsrc plugin. When a client connects to a malicious RFB/VNC server that advertises a 16bpp framebuffer and sends Hextile-encoded updates, the Hextile background fill path writes 32-bit pixel values into a buffer allocated for 16-bit pixels. This type mismatch causes an out-of-bounds heap write that can lead to denial of service (process crash) and potential memory corruption. | CVSS3: 7.1 | 0% Низкий | 22 дня назад | |
GHSA-f48p-mg4r-fhww A stack buffer overflow vulnerability was found in GStreamer's DTLS plugin. During a DTLS handshake, the peer certificate Subject Distinguished Name is printed into a fixed-size 2048-byte stack buffer without bounds checking. A remote unauthenticated attacker can send a certificate with an oversized Subject DN that exceeds the buffer, causing a stack buffer overflow and process crash, resulting in denial of service. | CVSS3: 7.5 | 0% Низкий | 22 дня назад | |
SUSE-SU-2026:3299-1 Security update for gstreamer-plugins-bad | 4 дня назад | |||
SUSE-SU-2026:3133-1 Security update for gstreamer-plugins-bad | 11 дней назад | |||
SUSE-SU-2026:3125-1 Security update for gstreamer-plugins-bad | 12 дней назад | |||
SUSE-SU-2026:3058-1 Security update for gstreamer-plugins-bad | 16 дней назад | |||
openSUSE-SU-2026:21370-1 Security update for gstreamer-plugins-bad | 14 дней назад |
Уязвимостей на страницу