Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 16

Количество 16

ubuntu логотип

CVE-2026-53705

около 2 месяцев назад

A flaw was found in GStreamer's WavPack audio decoder in gst-plugins-good. When processing a specially crafted WavPack file, an integer overflow in the buffer size calculation (4 * block_samples * channels) in gst_wavpack_dec_handle_frame() causes a very small heap allocation. The WavPack library then writes decoded audio samples far beyond the allocated buffer, resulting in heap memory corruption. This affects both 32-bit and 64-bit systems since the arithmetic is performed in 32-bit integers before promotion to the allocation size type. A remote attacker could use this flaw to crash an application or potentially execute arbitrary code by convincing a user to open a malicious WavPack audio file.

CVSS3: 7.6
EPSS: Низкий
redhat логотип

CVE-2026-53705

около 2 месяцев назад

A flaw was found in GStreamer's WavPack audio decoder in gst-plugins-good. When processing a specially crafted WavPack file, an integer overflow in the buffer size calculation (4 * block_samples * channels) in gst_wavpack_dec_handle_frame() causes a very small heap allocation. The WavPack library then writes decoded audio samples far beyond the allocated buffer, resulting in heap memory corruption. This affects both 32-bit and 64-bit systems since the arithmetic is performed in 32-bit integers before promotion to the allocation size type. A remote attacker could use this flaw to crash an application or potentially execute arbitrary code by convincing a user to open a malicious WavPack audio file.

CVSS3: 7.6
EPSS: Низкий
nvd логотип

CVE-2026-53705

около 2 месяцев назад

A flaw was found in GStreamer's WavPack audio decoder in gst-plugins-good. When processing a specially crafted WavPack file, an integer overflow in the buffer size calculation (4 * block_samples * channels) in gst_wavpack_dec_handle_frame() causes a very small heap allocation. The WavPack library then writes decoded audio samples far beyond the allocated buffer, resulting in heap memory corruption. This affects both 32-bit and 64-bit systems since the arithmetic is performed in 32-bit integers before promotion to the allocation size type. A remote attacker could use this flaw to crash an application or potentially execute arbitrary code by convincing a user to open a malicious WavPack audio file.

CVSS3: 7.6
EPSS: Низкий
debian логотип

CVE-2026-53705

около 2 месяцев назад

A flaw was found in GStreamer's WavPack audio decoder in gst-plugins-g ...

CVSS3: 7.6
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21240-1

26 дней назад

Security update for gstreamer-plugins-good

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2844-1

21 день назад

Security update for gstreamer-plugins-good

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2843-1

21 день назад

Security update for gstreamer-plugins-good

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2842-1

21 день назад

Security update for gstreamer-plugins-good

EPSS: Низкий
rocky логотип

RLSA-2026:37129

21 день назад

Important: gstreamer1-plugins-good security update

EPSS: Низкий
rocky логотип

RLSA-2026:36774

23 дня назад

Important: gstreamer1-plugins-good security update

EPSS: Низкий
rocky логотип

RLSA-2026:36675

21 день назад

Important: gstreamer1-plugins-good security update

EPSS: Низкий
github логотип

GHSA-rc6x-6x52-9whj

около 2 месяцев назад

A flaw was found in GStreamer's WavPack audio decoder in gst-plugins-good. When processing a specially crafted WavPack file, an integer overflow in the buffer size calculation (4 * block_samples * channels) in gst_wavpack_dec_handle_frame() causes a very small heap allocation. The WavPack library then writes decoded audio samples far beyond the allocated buffer, resulting in heap memory corruption. This affects both 32-bit and 64-bit systems since the arithmetic is performed in 32-bit integers before promotion to the allocation size type. A remote attacker could use this flaw to crash an application or potentially execute arbitrary code by convincing a user to open a malicious WavPack audio file.

CVSS3: 7.6
EPSS: Низкий
oracle-oval логотип

ELSA-2026-37129

23 дня назад

ELSA-2026-37129: gstreamer1-plugins-good security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-36774

24 дня назад

ELSA-2026-36774: gstreamer1-plugins-good security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-36675

16 дней назад

ELSA-2026-36675: gstreamer1-plugins-good security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2727-1

29 дней назад

Security update for gstreamer-plugins-good

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-53705

A flaw was found in GStreamer's WavPack audio decoder in gst-plugins-good. When processing a specially crafted WavPack file, an integer overflow in the buffer size calculation (4 * block_samples * channels) in gst_wavpack_dec_handle_frame() causes a very small heap allocation. The WavPack library then writes decoded audio samples far beyond the allocated buffer, resulting in heap memory corruption. This affects both 32-bit and 64-bit systems since the arithmetic is performed in 32-bit integers before promotion to the allocation size type. A remote attacker could use this flaw to crash an application or potentially execute arbitrary code by convincing a user to open a malicious WavPack audio file.

CVSS3: 7.6
0%
Низкий
около 2 месяцев назад
redhat логотип
CVE-2026-53705

A flaw was found in GStreamer's WavPack audio decoder in gst-plugins-good. When processing a specially crafted WavPack file, an integer overflow in the buffer size calculation (4 * block_samples * channels) in gst_wavpack_dec_handle_frame() causes a very small heap allocation. The WavPack library then writes decoded audio samples far beyond the allocated buffer, resulting in heap memory corruption. This affects both 32-bit and 64-bit systems since the arithmetic is performed in 32-bit integers before promotion to the allocation size type. A remote attacker could use this flaw to crash an application or potentially execute arbitrary code by convincing a user to open a malicious WavPack audio file.

CVSS3: 7.6
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-53705

A flaw was found in GStreamer's WavPack audio decoder in gst-plugins-good. When processing a specially crafted WavPack file, an integer overflow in the buffer size calculation (4 * block_samples * channels) in gst_wavpack_dec_handle_frame() causes a very small heap allocation. The WavPack library then writes decoded audio samples far beyond the allocated buffer, resulting in heap memory corruption. This affects both 32-bit and 64-bit systems since the arithmetic is performed in 32-bit integers before promotion to the allocation size type. A remote attacker could use this flaw to crash an application or potentially execute arbitrary code by convincing a user to open a malicious WavPack audio file.

CVSS3: 7.6
0%
Низкий
около 2 месяцев назад
debian логотип
CVE-2026-53705

A flaw was found in GStreamer's WavPack audio decoder in gst-plugins-g ...

CVSS3: 7.6
0%
Низкий
около 2 месяцев назад
suse-cvrf логотип
openSUSE-SU-2026:21240-1

Security update for gstreamer-plugins-good

0%
Низкий
26 дней назад
suse-cvrf логотип
SUSE-SU-2026:2844-1

Security update for gstreamer-plugins-good

0%
Низкий
21 день назад
suse-cvrf логотип
SUSE-SU-2026:2843-1

Security update for gstreamer-plugins-good

0%
Низкий
21 день назад
suse-cvrf логотип
SUSE-SU-2026:2842-1

Security update for gstreamer-plugins-good

0%
Низкий
21 день назад
rocky логотип
RLSA-2026:37129

Important: gstreamer1-plugins-good security update

0%
Низкий
21 день назад
rocky логотип
RLSA-2026:36774

Important: gstreamer1-plugins-good security update

0%
Низкий
23 дня назад
rocky логотип
RLSA-2026:36675

Important: gstreamer1-plugins-good security update

0%
Низкий
21 день назад
github логотип
GHSA-rc6x-6x52-9whj

A flaw was found in GStreamer's WavPack audio decoder in gst-plugins-good. When processing a specially crafted WavPack file, an integer overflow in the buffer size calculation (4 * block_samples * channels) in gst_wavpack_dec_handle_frame() causes a very small heap allocation. The WavPack library then writes decoded audio samples far beyond the allocated buffer, resulting in heap memory corruption. This affects both 32-bit and 64-bit systems since the arithmetic is performed in 32-bit integers before promotion to the allocation size type. A remote attacker could use this flaw to crash an application or potentially execute arbitrary code by convincing a user to open a malicious WavPack audio file.

CVSS3: 7.6
0%
Низкий
около 2 месяцев назад
oracle-oval логотип
ELSA-2026-37129

ELSA-2026-37129: gstreamer1-plugins-good security update (IMPORTANT)

23 дня назад
oracle-oval логотип
ELSA-2026-36774

ELSA-2026-36774: gstreamer1-plugins-good security update (IMPORTANT)

24 дня назад
oracle-oval логотип
ELSA-2026-36675

ELSA-2026-36675: gstreamer1-plugins-good security update (IMPORTANT)

16 дней назад
suse-cvrf логотип
SUSE-SU-2026:2727-1

Security update for gstreamer-plugins-good

29 дней назад

Уязвимостей на страницу