Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 10

Количество 10

github логотип

GHSA-mc62-3gf7-rphg

около 2 месяцев назад

A flaw was found in GStreamer's gst-plugins-bad package. When processing a specially crafted H.264 video file containing malformed MVC or SVC extension slice NAL units, a 1-byte heap out-of-bounds read can occur during parsing. This happens when the parser attempts to check slice boundary information without first verifying that the NAL unit contains enough data beyond the extension header. An attacker could exploit this by tricking a user into opening a malicious H.264 video file, potentially causing the application to crash or leak a single byte of heap memory.

CVSS3: 4.4
EPSS: Низкий
ubuntu логотип

CVE-2026-12892

около 2 месяцев назад

A flaw was found in GStreamer's gst-plugins-bad package. When processing a specially crafted H.264 video file containing malformed MVC or SVC extension slice NAL units, a 1-byte heap out-of-bounds read can occur during parsing. This happens when the parser attempts to check slice boundary information without first verifying that the NAL unit contains enough data beyond the extension header. An attacker could exploit this by tricking a user into opening a malicious H.264 video file, potentially causing the application to crash or leak a single byte of heap memory.

CVSS3: 4.4
EPSS: Низкий
redhat логотип

CVE-2026-12892

около 2 месяцев назад

A flaw was found in GStreamer's gst-plugins-bad package. When processing a specially crafted H.264 video file containing malformed MVC or SVC extension slice NAL units, a 1-byte heap out-of-bounds read can occur during parsing. This happens when the parser attempts to check slice boundary information without first verifying that the NAL unit contains enough data beyond the extension header. An attacker could exploit this by tricking a user into opening a malicious H.264 video file, potentially causing the application to crash or leak a single byte of heap memory.

CVSS3: 4.4
EPSS: Низкий
nvd логотип

CVE-2026-12892

около 2 месяцев назад

A flaw was found in GStreamer's gst-plugins-bad package. When processing a specially crafted H.264 video file containing malformed MVC or SVC extension slice NAL units, a 1-byte heap out-of-bounds read can occur during parsing. This happens when the parser attempts to check slice boundary information without first verifying that the NAL unit contains enough data beyond the extension header. An attacker could exploit this by tricking a user into opening a malicious H.264 video file, potentially causing the application to crash or leak a single byte of heap memory.

CVSS3: 4.4
EPSS: Низкий
debian логотип

CVE-2026-12892

около 2 месяцев назад

A flaw was found in GStreamer's gst-plugins-bad package. When processi ...

CVSS3: 4.4
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3299-1

22 дня назад

Security update for gstreamer-plugins-bad

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3133-1

30 дней назад

Security update for gstreamer-plugins-bad

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3125-1

30 дней назад

Security update for gstreamer-plugins-bad

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3058-1

около 1 месяца назад

Security update for gstreamer-plugins-bad

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21370-1

около 1 месяца назад

Security update for gstreamer-plugins-bad

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-mc62-3gf7-rphg

A flaw was found in GStreamer's gst-plugins-bad package. When processing a specially crafted H.264 video file containing malformed MVC or SVC extension slice NAL units, a 1-byte heap out-of-bounds read can occur during parsing. This happens when the parser attempts to check slice boundary information without first verifying that the NAL unit contains enough data beyond the extension header. An attacker could exploit this by tricking a user into opening a malicious H.264 video file, potentially causing the application to crash or leak a single byte of heap memory.

CVSS3: 4.4
0%
Низкий
около 2 месяцев назад
ubuntu логотип
CVE-2026-12892

A flaw was found in GStreamer's gst-plugins-bad package. When processing a specially crafted H.264 video file containing malformed MVC or SVC extension slice NAL units, a 1-byte heap out-of-bounds read can occur during parsing. This happens when the parser attempts to check slice boundary information without first verifying that the NAL unit contains enough data beyond the extension header. An attacker could exploit this by tricking a user into opening a malicious H.264 video file, potentially causing the application to crash or leak a single byte of heap memory.

CVSS3: 4.4
0%
Низкий
около 2 месяцев назад
redhat логотип
CVE-2026-12892

A flaw was found in GStreamer's gst-plugins-bad package. When processing a specially crafted H.264 video file containing malformed MVC or SVC extension slice NAL units, a 1-byte heap out-of-bounds read can occur during parsing. This happens when the parser attempts to check slice boundary information without first verifying that the NAL unit contains enough data beyond the extension header. An attacker could exploit this by tricking a user into opening a malicious H.264 video file, potentially causing the application to crash or leak a single byte of heap memory.

CVSS3: 4.4
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-12892

A flaw was found in GStreamer's gst-plugins-bad package. When processing a specially crafted H.264 video file containing malformed MVC or SVC extension slice NAL units, a 1-byte heap out-of-bounds read can occur during parsing. This happens when the parser attempts to check slice boundary information without first verifying that the NAL unit contains enough data beyond the extension header. An attacker could exploit this by tricking a user into opening a malicious H.264 video file, potentially causing the application to crash or leak a single byte of heap memory.

CVSS3: 4.4
0%
Низкий
около 2 месяцев назад
debian логотип
CVE-2026-12892

A flaw was found in GStreamer's gst-plugins-bad package. When processi ...

CVSS3: 4.4
0%
Низкий
около 2 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:3299-1

Security update for gstreamer-plugins-bad

22 дня назад
suse-cvrf логотип
SUSE-SU-2026:3133-1

Security update for gstreamer-plugins-bad

30 дней назад
suse-cvrf логотип
SUSE-SU-2026:3125-1

Security update for gstreamer-plugins-bad

30 дней назад
suse-cvrf логотип
SUSE-SU-2026:3058-1

Security update for gstreamer-plugins-bad

около 1 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:21370-1

Security update for gstreamer-plugins-bad

около 1 месяца назад

Уязвимостей на страницу