Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 19

Количество 19

github логотип

GHSA-rc6x-6x52-9whj

3 месяца назад

A flaw was found in GStreamer's WavPack audio decoder in gst-plugins-good. When processing a specially crafted WavPack file, an integer overflow in the buffer size calculation (4 * block_samples * channels) in gst_wavpack_dec_handle_frame() causes a very small heap allocation. The WavPack library then writes decoded audio samples far beyond the allocated buffer, resulting in heap memory corruption. This affects both 32-bit and 64-bit systems since the arithmetic is performed in 32-bit integers before promotion to the allocation size type. A remote attacker could use this flaw to crash an application or potentially execute arbitrary code by convincing a user to open a malicious WavPack audio file.

CVSS3: 7.6
EPSS: Низкий
ubuntu логотип

CVE-2026-53705

3 месяца назад

A flaw was found in GStreamer's WavPack audio decoder in gst-plugins-good. When processing a specially crafted WavPack file, an integer overflow in the buffer size calculation (4 * block_samples * channels) in gst_wavpack_dec_handle_frame() causes a very small heap allocation. The WavPack library then writes decoded audio samples far beyond the allocated buffer, resulting in heap memory corruption. This affects both 32-bit and 64-bit systems since the arithmetic is performed in 32-bit integers before promotion to the allocation size type. A remote attacker could use this flaw to crash an application or potentially execute arbitrary code by convincing a user to open a malicious WavPack audio file.

CVSS3: 7.6
EPSS: Низкий
redhat логотип

CVE-2026-53705

3 месяца назад

A flaw was found in GStreamer's WavPack audio decoder in gst-plugins-good. When processing a specially crafted WavPack file, an integer overflow in the buffer size calculation (4 * block_samples * channels) in gst_wavpack_dec_handle_frame() causes a very small heap allocation. The WavPack library then writes decoded audio samples far beyond the allocated buffer, resulting in heap memory corruption. This affects both 32-bit and 64-bit systems since the arithmetic is performed in 32-bit integers before promotion to the allocation size type. A remote attacker could use this flaw to crash an application or potentially execute arbitrary code by convincing a user to open a malicious WavPack audio file.

CVSS3: 7.6
EPSS: Низкий
nvd логотип

CVE-2026-53705

3 месяца назад

A flaw was found in GStreamer's WavPack audio decoder in gst-plugins-good. When processing a specially crafted WavPack file, an integer overflow in the buffer size calculation (4 * block_samples * channels) in gst_wavpack_dec_handle_frame() causes a very small heap allocation. The WavPack library then writes decoded audio samples far beyond the allocated buffer, resulting in heap memory corruption. This affects both 32-bit and 64-bit systems since the arithmetic is performed in 32-bit integers before promotion to the allocation size type. A remote attacker could use this flaw to crash an application or potentially execute arbitrary code by convincing a user to open a malicious WavPack audio file.

CVSS3: 7.6
EPSS: Низкий
debian логотип

CVE-2026-53705

3 месяца назад

A flaw was found in GStreamer's WavPack audio decoder in gst-plugins-g ...

CVSS3: 7.6
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21240-1

3 месяца назад

Security update for gstreamer-plugins-good

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2844-1

3 месяца назад

Security update for gstreamer-plugins-good

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2843-1

3 месяца назад

Security update for gstreamer-plugins-good

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2842-1

3 месяца назад

Security update for gstreamer-plugins-good

EPSS: Низкий
redos логотип

ROS-20260922-80-0012

3 дня назад

Уязвимость gstreamer1-plugins-good

CVSS3: 7.6
EPSS: Низкий
redos логотип

ROS-20260922-73-0010

3 дня назад

Уязвимость gstreamer1-plugins-good

CVSS3: 7.6
EPSS: Низкий
rocky логотип

RLSA-2026:37129

3 месяца назад

Important: gstreamer1-plugins-good security update

EPSS: Низкий
rocky логотип

RLSA-2026:36774

3 месяца назад

Important: gstreamer1-plugins-good security update

EPSS: Низкий
rocky логотип

RLSA-2026:36675

3 месяца назад

Important: gstreamer1-plugins-good security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-49603

около 1 месяца назад

ELSA-2026-49603: gstreamer1-plugins-good security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-37129

3 месяца назад

ELSA-2026-37129: gstreamer1-plugins-good security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-36774

3 месяца назад

ELSA-2026-36774: gstreamer1-plugins-good security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-36675

2 месяца назад

ELSA-2026-36675: gstreamer1-plugins-good security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2727-1

3 месяца назад

Security update for gstreamer-plugins-good

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-rc6x-6x52-9whj

A flaw was found in GStreamer's WavPack audio decoder in gst-plugins-good. When processing a specially crafted WavPack file, an integer overflow in the buffer size calculation (4 * block_samples * channels) in gst_wavpack_dec_handle_frame() causes a very small heap allocation. The WavPack library then writes decoded audio samples far beyond the allocated buffer, resulting in heap memory corruption. This affects both 32-bit and 64-bit systems since the arithmetic is performed in 32-bit integers before promotion to the allocation size type. A remote attacker could use this flaw to crash an application or potentially execute arbitrary code by convincing a user to open a malicious WavPack audio file.

CVSS3: 7.6
0%
Низкий
3 месяца назад
ubuntu логотип
CVE-2026-53705

A flaw was found in GStreamer's WavPack audio decoder in gst-plugins-good. When processing a specially crafted WavPack file, an integer overflow in the buffer size calculation (4 * block_samples * channels) in gst_wavpack_dec_handle_frame() causes a very small heap allocation. The WavPack library then writes decoded audio samples far beyond the allocated buffer, resulting in heap memory corruption. This affects both 32-bit and 64-bit systems since the arithmetic is performed in 32-bit integers before promotion to the allocation size type. A remote attacker could use this flaw to crash an application or potentially execute arbitrary code by convincing a user to open a malicious WavPack audio file.

CVSS3: 7.6
0%
Низкий
3 месяца назад
redhat логотип
CVE-2026-53705

A flaw was found in GStreamer's WavPack audio decoder in gst-plugins-good. When processing a specially crafted WavPack file, an integer overflow in the buffer size calculation (4 * block_samples * channels) in gst_wavpack_dec_handle_frame() causes a very small heap allocation. The WavPack library then writes decoded audio samples far beyond the allocated buffer, resulting in heap memory corruption. This affects both 32-bit and 64-bit systems since the arithmetic is performed in 32-bit integers before promotion to the allocation size type. A remote attacker could use this flaw to crash an application or potentially execute arbitrary code by convincing a user to open a malicious WavPack audio file.

CVSS3: 7.6
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-53705

A flaw was found in GStreamer's WavPack audio decoder in gst-plugins-good. When processing a specially crafted WavPack file, an integer overflow in the buffer size calculation (4 * block_samples * channels) in gst_wavpack_dec_handle_frame() causes a very small heap allocation. The WavPack library then writes decoded audio samples far beyond the allocated buffer, resulting in heap memory corruption. This affects both 32-bit and 64-bit systems since the arithmetic is performed in 32-bit integers before promotion to the allocation size type. A remote attacker could use this flaw to crash an application or potentially execute arbitrary code by convincing a user to open a malicious WavPack audio file.

CVSS3: 7.6
0%
Низкий
3 месяца назад
debian логотип
CVE-2026-53705

A flaw was found in GStreamer's WavPack audio decoder in gst-plugins-g ...

CVSS3: 7.6
0%
Низкий
3 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:21240-1

Security update for gstreamer-plugins-good

0%
Низкий
3 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2844-1

Security update for gstreamer-plugins-good

0%
Низкий
3 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2843-1

Security update for gstreamer-plugins-good

0%
Низкий
3 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2842-1

Security update for gstreamer-plugins-good

0%
Низкий
3 месяца назад
redos логотип
ROS-20260922-80-0012

Уязвимость gstreamer1-plugins-good

CVSS3: 7.6
0%
Низкий
3 дня назад
redos логотип
ROS-20260922-73-0010

Уязвимость gstreamer1-plugins-good

CVSS3: 7.6
0%
Низкий
3 дня назад
rocky логотип
RLSA-2026:37129

Important: gstreamer1-plugins-good security update

0%
Низкий
3 месяца назад
rocky логотип
RLSA-2026:36774

Important: gstreamer1-plugins-good security update

0%
Низкий
3 месяца назад
rocky логотип
RLSA-2026:36675

Important: gstreamer1-plugins-good security update

0%
Низкий
3 месяца назад
oracle-oval логотип
ELSA-2026-49603

ELSA-2026-49603: gstreamer1-plugins-good security update (IMPORTANT)

0%
Низкий
около 1 месяца назад
oracle-oval логотип
ELSA-2026-37129

ELSA-2026-37129: gstreamer1-plugins-good security update (IMPORTANT)

0%
Низкий
3 месяца назад
oracle-oval логотип
ELSA-2026-36774

ELSA-2026-36774: gstreamer1-plugins-good security update (IMPORTANT)

0%
Низкий
3 месяца назад
oracle-oval логотип
ELSA-2026-36675

ELSA-2026-36675: gstreamer1-plugins-good security update (IMPORTANT)

0%
Низкий
2 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2727-1

Security update for gstreamer-plugins-good

3 месяца назад

Уязвимостей на страницу