Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 22

Количество 22

rocky логотип

RLSA-2025:7178

12 месяцев назад

Moderate: gstreamer1, gstreamer1-plugins-bad-free, gstreamer1-plugins-ugly-free, and gstreamer1-rtsp-server security update

EPSS: Низкий
oracle-oval логотип

ELSA-2025-7178

больше 1 года назад

ELSA-2025-7178: gstreamer1, gstreamer1-plugins-bad-free, gstreamer1-plugins-ugly-free, and gstreamer1-rtsp-server security update (MODERATE)

EPSS: Низкий
ubuntu логотип

CVE-2024-0444

больше 2 лет назад

GStreamer AV1 Video Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the parsing of tile list data within AV1-encoded video files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-22873.

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2024-0444

больше 2 лет назад

GStreamer AV1 Video Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the parsing of tile list data within AV1-encoded video files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-22873.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2024-0444

больше 2 лет назад

GStreamer AV1 Video Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the parsing of tile list data within AV1-encoded video files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-22873.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2024-0444

больше 2 лет назад

GStreamer AV1 Video Parsing Stack-based Buffer Overflow Remote Code Ex ...

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2024-4453

больше 2 лет назад

GStreamer EXIF Metadata Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the parsing of EXIF metadata. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before allocating a buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. . Was ZDI-CAN-23896.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2024-4453

больше 2 лет назад

GStreamer EXIF Metadata Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the parsing of EXIF metadata. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before allocating a buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. . Was ZDI-CAN-23896.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2024-4453

больше 2 лет назад

GStreamer EXIF Metadata Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the parsing of EXIF metadata. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before allocating a buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. . Was ZDI-CAN-23896.

CVSS3: 7.8
EPSS: Низкий
debian логотип

CVE-2024-4453

больше 2 лет назад

GStreamer EXIF Metadata Parsing Integer Overflow Remote Code Execution ...

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-35hr-69cj-v3x3

больше 2 лет назад

GStreamer AV1 Video Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the parsing of tile list data within AV1-encoded video files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-22873.

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2024-06904

больше 2 лет назад

Уязвимость мультимедийного фреймворка Gstreamer, связанная с переполнением буфера на стеке, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:1945-1

больше 2 лет назад

Security update for gstreamer-plugins-base

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:1910-1

больше 2 лет назад

Security update for gstreamer-plugins-base

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:1893-1

больше 2 лет назад

Security update for gstreamer-plugins-base

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:1886-1

больше 2 лет назад

Security update for gstreamer-plugins-base

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:1882-1

больше 2 лет назад

Security update for gstreamer-plugins-base

EPSS: Низкий
rocky логотип

RLSA-2024:9056

почти 2 года назад

Moderate: gstreamer1-plugins-base security update

EPSS: Низкий
github логотип

GHSA-wxq9-8346-gp9m

больше 2 лет назад

GStreamer EXIF Metadata Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the parsing of EXIF metadata. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before allocating a buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. . Was ZDI-CAN-23896.

CVSS3: 7.8
EPSS: Низкий
oracle-oval логотип

ELSA-2024-9056

почти 2 года назад

ELSA-2024-9056: gstreamer1-plugins-base security update (MODERATE)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
rocky логотип
RLSA-2025:7178

Moderate: gstreamer1, gstreamer1-plugins-bad-free, gstreamer1-plugins-ugly-free, and gstreamer1-rtsp-server security update

12 месяцев назад
oracle-oval логотип
ELSA-2025-7178

ELSA-2025-7178: gstreamer1, gstreamer1-plugins-bad-free, gstreamer1-plugins-ugly-free, and gstreamer1-rtsp-server security update (MODERATE)

больше 1 года назад
ubuntu логотип
CVE-2024-0444

GStreamer AV1 Video Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the parsing of tile list data within AV1-encoded video files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-22873.

CVSS3: 8.8
2%
Низкий
больше 2 лет назад
redhat логотип
CVE-2024-0444

GStreamer AV1 Video Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the parsing of tile list data within AV1-encoded video files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-22873.

CVSS3: 7.5
2%
Низкий
больше 2 лет назад
nvd логотип
CVE-2024-0444

GStreamer AV1 Video Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the parsing of tile list data within AV1-encoded video files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-22873.

CVSS3: 8.8
2%
Низкий
больше 2 лет назад
debian логотип
CVE-2024-0444

GStreamer AV1 Video Parsing Stack-based Buffer Overflow Remote Code Ex ...

CVSS3: 8.8
2%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2024-4453

GStreamer EXIF Metadata Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the parsing of EXIF metadata. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before allocating a buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. . Was ZDI-CAN-23896.

CVSS3: 7.8
2%
Низкий
больше 2 лет назад
redhat логотип
CVE-2024-4453

GStreamer EXIF Metadata Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the parsing of EXIF metadata. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before allocating a buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. . Was ZDI-CAN-23896.

CVSS3: 7.8
2%
Низкий
больше 2 лет назад
nvd логотип
CVE-2024-4453

GStreamer EXIF Metadata Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the parsing of EXIF metadata. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before allocating a buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. . Was ZDI-CAN-23896.

CVSS3: 7.8
2%
Низкий
больше 2 лет назад
debian логотип
CVE-2024-4453

GStreamer EXIF Metadata Parsing Integer Overflow Remote Code Execution ...

CVSS3: 7.8
2%
Низкий
больше 2 лет назад
github логотип
GHSA-35hr-69cj-v3x3

GStreamer AV1 Video Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the parsing of tile list data within AV1-encoded video files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-22873.

CVSS3: 7.5
2%
Низкий
больше 2 лет назад
fstec логотип
BDU:2024-06904

Уязвимость мультимедийного фреймворка Gstreamer, связанная с переполнением буфера на стеке, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

CVSS3: 7.5
2%
Низкий
больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2024:1945-1

Security update for gstreamer-plugins-base

2%
Низкий
больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2024:1910-1

Security update for gstreamer-plugins-base

2%
Низкий
больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2024:1893-1

Security update for gstreamer-plugins-base

2%
Низкий
больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2024:1886-1

Security update for gstreamer-plugins-base

2%
Низкий
больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2024:1882-1

Security update for gstreamer-plugins-base

2%
Низкий
больше 2 лет назад
rocky логотип
RLSA-2024:9056

Moderate: gstreamer1-plugins-base security update

2%
Низкий
почти 2 года назад
github логотип
GHSA-wxq9-8346-gp9m

GStreamer EXIF Metadata Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the parsing of EXIF metadata. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before allocating a buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. . Was ZDI-CAN-23896.

CVSS3: 7.8
2%
Низкий
больше 2 лет назад
oracle-oval логотип
ELSA-2024-9056

ELSA-2024-9056: gstreamer1-plugins-base security update (MODERATE)

2%
Низкий
почти 2 года назад

Уязвимостей на страницу