Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 11

Количество 11

ubuntu логотип

CVE-2026-53703

3 месяца назад

A vulnerability was found in the GStreamer RealMedia demuxer (gst-plugins-ugly). When processing a RealMedia (.rm) file, the demuxer parses MDPR (media properties) chunks to configure audio streams. For audio stream header versions 4 and 5, the parser reads fields such as codec type, packet size, sample rate, channel count, and extra codec data length from fixed offsets within the chunk without first checking that the chunk contains enough data. If a malicious file provides an MDPR chunk that is too small to contain a complete audio stream header, the parser reads beyond the end of the buffer. This can cause the application to crash. In some cases, bytes read past the buffer boundary may be incorporated into stream metadata, which could result in limited information disclosure.

CVSS3: 7.1
EPSS: Низкий
redhat логотип

CVE-2026-53703

3 месяца назад

A vulnerability was found in the GStreamer RealMedia demuxer (gst-plugins-ugly). When processing a RealMedia (.rm) file, the demuxer parses MDPR (media properties) chunks to configure audio streams. For audio stream header versions 4 and 5, the parser reads fields such as codec type, packet size, sample rate, channel count, and extra codec data length from fixed offsets within the chunk without first checking that the chunk contains enough data. If a malicious file provides an MDPR chunk that is too small to contain a complete audio stream header, the parser reads beyond the end of the buffer. This can cause the application to crash. In some cases, bytes read past the buffer boundary may be incorporated into stream metadata, which could result in limited information disclosure.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-53703

3 месяца назад

A vulnerability was found in the GStreamer RealMedia demuxer (gst-plugins-ugly). When processing a RealMedia (.rm) file, the demuxer parses MDPR (media properties) chunks to configure audio streams. For audio stream header versions 4 and 5, the parser reads fields such as codec type, packet size, sample rate, channel count, and extra codec data length from fixed offsets within the chunk without first checking that the chunk contains enough data. If a malicious file provides an MDPR chunk that is too small to contain a complete audio stream header, the parser reads beyond the end of the buffer. This can cause the application to crash. In some cases, bytes read past the buffer boundary may be incorporated into stream metadata, which could result in limited information disclosure.

CVSS3: 7.1
EPSS: Низкий
debian логотип

CVE-2026-53703

3 месяца назад

A vulnerability was found in the GStreamer RealMedia demuxer (gst-plug ...

CVSS3: 7.1
EPSS: Низкий
redos логотип

ROS-20260922-80-0040

3 дня назад

Уязвимость gstreamer1-plugins-ugly-free

CVSS3: 7.1
EPSS: Низкий
redos логотип

ROS-20260922-73-0028

3 дня назад

Уязвимость gstreamer1-plugins-ugly

CVSS3: 7.1
EPSS: Низкий
rocky логотип

RLSA-2026:36673

3 месяца назад

Moderate: gstreamer1-plugins-ugly-free security update

EPSS: Низкий
github логотип

GHSA-hghw-p2mw-fvch

3 месяца назад

A vulnerability was found in the GStreamer RealMedia demuxer (gst-plugins-ugly). When processing a RealMedia (.rm) file, the demuxer parses MDPR (media properties) chunks to configure audio streams. For audio stream header versions 4 and 5, the parser reads fields such as codec type, packet size, sample rate, channel count, and extra codec data length from fixed offsets within the chunk without first checking that the chunk contains enough data. If a malicious file provides an MDPR chunk that is too small to contain a complete audio stream header, the parser reads beyond the end of the buffer. This can cause the application to crash. In some cases, bytes read past the buffer boundary may be incorporated into stream metadata, which could result in limited information disclosure.

CVSS3: 7.1
EPSS: Низкий
oracle-oval логотип

ELSA-2026-36673

2 месяца назад

ELSA-2026-36673: gstreamer1-plugins-ugly-free security update (MODERATE)

EPSS: Низкий
rocky логотип

RLSA-2026:36674

3 месяца назад

Moderate: gstreamer1-plugins-ugly-free security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-36674

3 месяца назад

ELSA-2026-36674: gstreamer1-plugins-ugly-free security update (MODERATE)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-53703

A vulnerability was found in the GStreamer RealMedia demuxer (gst-plugins-ugly). When processing a RealMedia (.rm) file, the demuxer parses MDPR (media properties) chunks to configure audio streams. For audio stream header versions 4 and 5, the parser reads fields such as codec type, packet size, sample rate, channel count, and extra codec data length from fixed offsets within the chunk without first checking that the chunk contains enough data. If a malicious file provides an MDPR chunk that is too small to contain a complete audio stream header, the parser reads beyond the end of the buffer. This can cause the application to crash. In some cases, bytes read past the buffer boundary may be incorporated into stream metadata, which could result in limited information disclosure.

CVSS3: 7.1
0%
Низкий
3 месяца назад
redhat логотип
CVE-2026-53703

A vulnerability was found in the GStreamer RealMedia demuxer (gst-plugins-ugly). When processing a RealMedia (.rm) file, the demuxer parses MDPR (media properties) chunks to configure audio streams. For audio stream header versions 4 and 5, the parser reads fields such as codec type, packet size, sample rate, channel count, and extra codec data length from fixed offsets within the chunk without first checking that the chunk contains enough data. If a malicious file provides an MDPR chunk that is too small to contain a complete audio stream header, the parser reads beyond the end of the buffer. This can cause the application to crash. In some cases, bytes read past the buffer boundary may be incorporated into stream metadata, which could result in limited information disclosure.

CVSS3: 7.1
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-53703

A vulnerability was found in the GStreamer RealMedia demuxer (gst-plugins-ugly). When processing a RealMedia (.rm) file, the demuxer parses MDPR (media properties) chunks to configure audio streams. For audio stream header versions 4 and 5, the parser reads fields such as codec type, packet size, sample rate, channel count, and extra codec data length from fixed offsets within the chunk without first checking that the chunk contains enough data. If a malicious file provides an MDPR chunk that is too small to contain a complete audio stream header, the parser reads beyond the end of the buffer. This can cause the application to crash. In some cases, bytes read past the buffer boundary may be incorporated into stream metadata, which could result in limited information disclosure.

CVSS3: 7.1
0%
Низкий
3 месяца назад
debian логотип
CVE-2026-53703

A vulnerability was found in the GStreamer RealMedia demuxer (gst-plug ...

CVSS3: 7.1
0%
Низкий
3 месяца назад
redos логотип
ROS-20260922-80-0040

Уязвимость gstreamer1-plugins-ugly-free

CVSS3: 7.1
0%
Низкий
3 дня назад
redos логотип
ROS-20260922-73-0028

Уязвимость gstreamer1-plugins-ugly

CVSS3: 7.1
0%
Низкий
3 дня назад
rocky логотип
RLSA-2026:36673

Moderate: gstreamer1-plugins-ugly-free security update

0%
Низкий
3 месяца назад
github логотип
GHSA-hghw-p2mw-fvch

A vulnerability was found in the GStreamer RealMedia demuxer (gst-plugins-ugly). When processing a RealMedia (.rm) file, the demuxer parses MDPR (media properties) chunks to configure audio streams. For audio stream header versions 4 and 5, the parser reads fields such as codec type, packet size, sample rate, channel count, and extra codec data length from fixed offsets within the chunk without first checking that the chunk contains enough data. If a malicious file provides an MDPR chunk that is too small to contain a complete audio stream header, the parser reads beyond the end of the buffer. This can cause the application to crash. In some cases, bytes read past the buffer boundary may be incorporated into stream metadata, which could result in limited information disclosure.

CVSS3: 7.1
0%
Низкий
3 месяца назад
oracle-oval логотип
ELSA-2026-36673

ELSA-2026-36673: gstreamer1-plugins-ugly-free security update (MODERATE)

0%
Низкий
2 месяца назад
rocky логотип
RLSA-2026:36674

Moderate: gstreamer1-plugins-ugly-free security update

3 месяца назад
oracle-oval логотип
ELSA-2026-36674

ELSA-2026-36674: gstreamer1-plugins-ugly-free security update (MODERATE)

3 месяца назад

Уязвимостей на страницу