Логотип exploitDog
bind:"CVE-2024-4453" OR bind:"CVE-2024-0444"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2024-4453" OR bind:"CVE-2024-0444"

Количество 21

Количество 21

oracle-oval логотип

ELSA-2025-7178

около 1 месяца назад

ELSA-2025-7178: gstreamer1, gstreamer1-plugins-bad-free, gstreamer1-plugins-ugly-free, and gstreamer1-rtsp-server security update (MODERATE)

EPSS: Низкий
ubuntu логотип

CVE-2024-0444

около 1 года назад

GStreamer AV1 Video Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the parsing of tile list data within AV1-encoded video files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-22873.

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2024-0444

около 1 года назад

GStreamer AV1 Video Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the parsing of tile list data within AV1-encoded video files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-22873.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2024-0444

около 1 года назад

GStreamer AV1 Video Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the parsing of tile list data within AV1-encoded video files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-22873.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2024-0444

около 1 года назад

GStreamer AV1 Video Parsing Stack-based Buffer Overflow Remote Code Ex ...

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2024-4453

около 1 года назад

GStreamer EXIF Metadata Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the parsing of EXIF metadata. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before allocating a buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. . Was ZDI-CAN-23896.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2024-4453

около 1 года назад

GStreamer EXIF Metadata Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the parsing of EXIF metadata. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before allocating a buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. . Was ZDI-CAN-23896.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2024-4453

около 1 года назад

GStreamer EXIF Metadata Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the parsing of EXIF metadata. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before allocating a buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. . Was ZDI-CAN-23896.

CVSS3: 7.8
EPSS: Низкий
debian логотип

CVE-2024-4453

около 1 года назад

GStreamer EXIF Metadata Parsing Integer Overflow Remote Code Execution ...

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-35hr-69cj-v3x3

около 1 года назад

GStreamer AV1 Video Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the parsing of tile list data within AV1-encoded video files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-22873.

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2024-06904

больше 1 года назад

Уязвимость мультимедийного фреймворка Gstreamer, связанная с переполнением буфера на стеке, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:1945-1

около 1 года назад

Security update for gstreamer-plugins-base

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:1910-1

около 1 года назад

Security update for gstreamer-plugins-base

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:1893-1

около 1 года назад

Security update for gstreamer-plugins-base

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:1886-1

около 1 года назад

Security update for gstreamer-plugins-base

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:1882-1

около 1 года назад

Security update for gstreamer-plugins-base

EPSS: Низкий
rocky логотип

RLSA-2024:9056

7 месяцев назад

Moderate: gstreamer1-plugins-base security update

EPSS: Низкий
github логотип

GHSA-wxq9-8346-gp9m

около 1 года назад

GStreamer EXIF Metadata Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the parsing of EXIF metadata. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before allocating a buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. . Was ZDI-CAN-23896.

CVSS3: 7.8
EPSS: Низкий
oracle-oval логотип

ELSA-2024-9056

8 месяцев назад

ELSA-2024-9056: gstreamer1-plugins-base security update (MODERATE)

EPSS: Низкий
fstec логотип

BDU:2024-04000

около 1 года назад

Уязвимость мультимедийного фреймворка Gstreamer, связанная с целочисленным переполнением, позволяющая нарушителю выполнить произвольный код

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
oracle-oval логотип
ELSA-2025-7178

ELSA-2025-7178: gstreamer1, gstreamer1-plugins-bad-free, gstreamer1-plugins-ugly-free, and gstreamer1-rtsp-server security update (MODERATE)

около 1 месяца назад
ubuntu логотип
CVE-2024-0444

GStreamer AV1 Video Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the parsing of tile list data within AV1-encoded video files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-22873.

CVSS3: 8.8
4%
Низкий
около 1 года назад
redhat логотип
CVE-2024-0444

GStreamer AV1 Video Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the parsing of tile list data within AV1-encoded video files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-22873.

CVSS3: 7.5
4%
Низкий
около 1 года назад
nvd логотип
CVE-2024-0444

GStreamer AV1 Video Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the parsing of tile list data within AV1-encoded video files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-22873.

CVSS3: 8.8
4%
Низкий
около 1 года назад
debian логотип
CVE-2024-0444

GStreamer AV1 Video Parsing Stack-based Buffer Overflow Remote Code Ex ...

CVSS3: 8.8
4%
Низкий
около 1 года назад
ubuntu логотип
CVE-2024-4453

GStreamer EXIF Metadata Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the parsing of EXIF metadata. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before allocating a buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. . Was ZDI-CAN-23896.

CVSS3: 7.8
2%
Низкий
около 1 года назад
redhat логотип
CVE-2024-4453

GStreamer EXIF Metadata Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the parsing of EXIF metadata. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before allocating a buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. . Was ZDI-CAN-23896.

CVSS3: 7.8
2%
Низкий
около 1 года назад
nvd логотип
CVE-2024-4453

GStreamer EXIF Metadata Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the parsing of EXIF metadata. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before allocating a buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. . Was ZDI-CAN-23896.

CVSS3: 7.8
2%
Низкий
около 1 года назад
debian логотип
CVE-2024-4453

GStreamer EXIF Metadata Parsing Integer Overflow Remote Code Execution ...

CVSS3: 7.8
2%
Низкий
около 1 года назад
github логотип
GHSA-35hr-69cj-v3x3

GStreamer AV1 Video Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the parsing of tile list data within AV1-encoded video files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-22873.

CVSS3: 7.5
4%
Низкий
около 1 года назад
fstec логотип
BDU:2024-06904

Уязвимость мультимедийного фреймворка Gstreamer, связанная с переполнением буфера на стеке, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

CVSS3: 7.5
4%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2024:1945-1

Security update for gstreamer-plugins-base

2%
Низкий
около 1 года назад
suse-cvrf логотип
SUSE-SU-2024:1910-1

Security update for gstreamer-plugins-base

2%
Низкий
около 1 года назад
suse-cvrf логотип
SUSE-SU-2024:1893-1

Security update for gstreamer-plugins-base

2%
Низкий
около 1 года назад
suse-cvrf логотип
SUSE-SU-2024:1886-1

Security update for gstreamer-plugins-base

2%
Низкий
около 1 года назад
suse-cvrf логотип
SUSE-SU-2024:1882-1

Security update for gstreamer-plugins-base

2%
Низкий
около 1 года назад
rocky логотип
RLSA-2024:9056

Moderate: gstreamer1-plugins-base security update

2%
Низкий
7 месяцев назад
github логотип
GHSA-wxq9-8346-gp9m

GStreamer EXIF Metadata Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the parsing of EXIF metadata. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before allocating a buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. . Was ZDI-CAN-23896.

CVSS3: 7.8
2%
Низкий
около 1 года назад
oracle-oval логотип
ELSA-2024-9056

ELSA-2024-9056: gstreamer1-plugins-base security update (MODERATE)

8 месяцев назад
fstec логотип
BDU:2024-04000

Уязвимость мультимедийного фреймворка Gstreamer, связанная с целочисленным переполнением, позволяющая нарушителю выполнить произвольный код

CVSS3: 7.8
2%
Низкий
около 1 года назад

Уязвимостей на страницу