Логотип exploitDog
bind:CVE-2023-37328
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-37328

Количество 16

Количество 16

ubuntu логотип

CVE-2023-37328

больше 1 года назад

GStreamer PGS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the parsing of PGS subtitle files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. . Was ZDI-CAN-20994.

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2023-37328

больше 2 лет назад

GStreamer PGS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the parsing of PGS subtitle files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. . Was ZDI-CAN-20994.

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2023-37328

больше 1 года назад

GStreamer PGS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the parsing of PGS subtitle files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. . Was ZDI-CAN-20994.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2023-37328

больше 1 года назад

GStreamer PGS File Parsing Heap-based Buffer Overflow Remote Code Exec ...

CVSS3: 8.8
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:3402-1

около 2 лет назад

Security update for gstreamer-plugins-base

EPSS: Низкий
rocky логотип

RLSA-2024:3088

6 месяцев назад

Moderate: gstreamer1-plugins-base security update

EPSS: Низкий
rocky логотип

RLSA-2024:2302

больше 1 года назад

Moderate: gstreamer1-plugins-base security update

EPSS: Низкий
github логотип

GHSA-cvqg-h5hx-c2m4

больше 1 года назад

GStreamer PGS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the parsing of PGS subtitle files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-20994.

CVSS3: 8.8
EPSS: Низкий
oracle-oval логотип

ELSA-2024-3088

больше 1 года назад

ELSA-2024-3088: gstreamer1-plugins-base security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-2302

больше 1 года назад

ELSA-2024-2302: gstreamer1-plugins-base security update (MODERATE)

EPSS: Низкий
fstec логотип

BDU:2023-03624

больше 2 лет назад

Уязвимость компонента анализа субтитров subparse мультимедийного фреймворка Gstreamer, позволяющая нарушителю выполнить произвольный код

CVSS3: 8.8
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:3265-1

больше 2 лет назад

Security update for gstreamer-plugins-base

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:3250-1

больше 2 лет назад

Security update for gstreamer-plugins-base

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:3236-1

больше 2 лет назад

Security update for gstreamer-plugins-base

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:3221-1

больше 2 лет назад

Security update for gstreamer-plugins-base

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:3801-1

около 2 лет назад

Security update for gstreamer-plugins-base

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2023-37328

GStreamer PGS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the parsing of PGS subtitle files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. . Was ZDI-CAN-20994.

CVSS3: 8.8
8%
Низкий
больше 1 года назад
redhat логотип
CVE-2023-37328

GStreamer PGS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the parsing of PGS subtitle files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. . Was ZDI-CAN-20994.

CVSS3: 5.5
8%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-37328

GStreamer PGS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the parsing of PGS subtitle files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. . Was ZDI-CAN-20994.

CVSS3: 8.8
8%
Низкий
больше 1 года назад
debian логотип
CVE-2023-37328

GStreamer PGS File Parsing Heap-based Buffer Overflow Remote Code Exec ...

CVSS3: 8.8
8%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2023:3402-1

Security update for gstreamer-plugins-base

8%
Низкий
около 2 лет назад
rocky логотип
RLSA-2024:3088

Moderate: gstreamer1-plugins-base security update

8%
Низкий
6 месяцев назад
rocky логотип
RLSA-2024:2302

Moderate: gstreamer1-plugins-base security update

8%
Низкий
больше 1 года назад
github логотип
GHSA-cvqg-h5hx-c2m4

GStreamer PGS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the parsing of PGS subtitle files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-20994.

CVSS3: 8.8
8%
Низкий
больше 1 года назад
oracle-oval логотип
ELSA-2024-3088

ELSA-2024-3088: gstreamer1-plugins-base security update (MODERATE)

больше 1 года назад
oracle-oval логотип
ELSA-2024-2302

ELSA-2024-2302: gstreamer1-plugins-base security update (MODERATE)

больше 1 года назад
fstec логотип
BDU:2023-03624

Уязвимость компонента анализа субтитров subparse мультимедийного фреймворка Gstreamer, позволяющая нарушителю выполнить произвольный код

CVSS3: 8.8
8%
Низкий
больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:3265-1

Security update for gstreamer-plugins-base

больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:3250-1

Security update for gstreamer-plugins-base

больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:3236-1

Security update for gstreamer-plugins-base

больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:3221-1

Security update for gstreamer-plugins-base

больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:3801-1

Security update for gstreamer-plugins-base

около 2 лет назад

Уязвимостей на страницу