Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 36

Количество 36

ubuntu логотип

CVE-2026-18299

около 1 месяца назад

GStreamer rtpsbcdepay Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the processing of RTP payload elements. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29787.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2026-18299

около 1 месяца назад

GStreamer rtpsbcdepay Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the processing of RTP payload elements. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29787.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2026-18299

около 1 месяца назад

GStreamer rtpsbcdepay Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the processing of RTP payload elements. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29787.

CVSS3: 7.8
EPSS: Низкий
debian логотип

CVE-2026-18299

около 1 месяца назад

GStreamer rtpsbcdepay Use-After-Free Remote Code Execution Vulnerabili ...

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2026-18298

около 1 месяца назад

GStreamer PNG File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PNG files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29581.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2026-18298

около 1 месяца назад

GStreamer PNG File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PNG files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29581.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-18298

около 1 месяца назад

GStreamer PNG File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PNG files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29581.

CVSS3: 7.8
EPSS: Низкий
debian логотип

CVE-2026-18298

около 1 месяца назад

GStreamer PNG File Parsing Heap-based Buffer Overflow Remote Code Exec ...

CVSS3: 7.8
EPSS: Низкий
redos логотип

ROS-20260922-80-0043

3 дня назад

Уязвимость gstreamer1-plugins-good

CVSS2: 7.2
EPSS: Низкий
redos логотип

ROS-20260922-80-0001

3 дня назад

Уязвимость gstreamer1-plugins-good

CVSS2: 7.2
EPSS: Низкий
redos логотип

ROS-20260922-73-0030

3 дня назад

Уязвимость gstreamer1-plugins-good

CVSS2: 7.2
EPSS: Низкий
redos логотип

ROS-20260922-73-0001

3 дня назад

Уязвимость gstreamer1-plugins-good

CVSS2: 7.2
EPSS: Низкий
rocky логотип

RLSA-2026:59972

29 дней назад

Important: gstreamer1-plugins-good security update

EPSS: Низкий
github логотип

GHSA-7xww-j5h2-23gh

около 1 месяца назад

GStreamer rtpsbcdepay Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the processing of RTP payload elements. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29787.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-5gr2-2c8f-ph26

около 1 месяца назад

GStreamer PNG File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PNG files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29581.

CVSS3: 7.8
EPSS: Низкий
oracle-oval логотип

ELSA-2026-59972

30 дней назад

ELSA-2026-59972: gstreamer1-plugins-good security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-18299

GStreamer rtpsbcdepay Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the processing of RTP payload elements. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29787.

CVSS3: 7.8
0%
Низкий
около 1 месяца назад
redhat логотип
CVE-2026-18299

GStreamer rtpsbcdepay Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the processing of RTP payload elements. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29787.

CVSS3: 8.8
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-18299

GStreamer rtpsbcdepay Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the processing of RTP payload elements. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29787.

CVSS3: 7.8
0%
Низкий
около 1 месяца назад
debian логотип
CVE-2026-18299

GStreamer rtpsbcdepay Use-After-Free Remote Code Execution Vulnerabili ...

CVSS3: 7.8
0%
Низкий
около 1 месяца назад
ubuntu логотип
CVE-2026-18298

GStreamer PNG File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PNG files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29581.

CVSS3: 7.8
0%
Низкий
около 1 месяца назад
redhat логотип
CVE-2026-18298

GStreamer PNG File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PNG files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29581.

CVSS3: 7.8
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-18298

GStreamer PNG File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PNG files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29581.

CVSS3: 7.8
0%
Низкий
около 1 месяца назад
debian логотип
CVE-2026-18298

GStreamer PNG File Parsing Heap-based Buffer Overflow Remote Code Exec ...

CVSS3: 7.8
0%
Низкий
около 1 месяца назад
redos логотип
ROS-20260922-80-0043

Уязвимость gstreamer1-plugins-good

CVSS2: 7.2
0%
Низкий
3 дня назад
redos логотип
ROS-20260922-80-0001

Уязвимость gstreamer1-plugins-good

CVSS2: 7.2
0%
Низкий
3 дня назад
redos логотип
ROS-20260922-73-0030

Уязвимость gstreamer1-plugins-good

CVSS2: 7.2
0%
Низкий
3 дня назад
redos логотип
ROS-20260922-73-0001

Уязвимость gstreamer1-plugins-good

CVSS2: 7.2
0%
Низкий
3 дня назад
rocky логотип
RLSA-2026:59972

Important: gstreamer1-plugins-good security update

0%
Низкий
29 дней назад
github логотип
GHSA-7xww-j5h2-23gh

GStreamer rtpsbcdepay Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the processing of RTP payload elements. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29787.

CVSS3: 7.8
0%
Низкий
около 1 месяца назад
github логотип
GHSA-5gr2-2c8f-ph26

GStreamer PNG File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PNG files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29581.

CVSS3: 7.8
0%
Низкий
около 1 месяца назад
oracle-oval логотип
ELSA-2026-59972

ELSA-2026-59972: gstreamer1-plugins-good security update (IMPORTANT)

0%
Низкий
30 дней назад

Уязвимостей на страницу