Логотип exploitDog
bind:CVE-2026-2920
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2026-2920

Количество 14

Количество 14

ubuntu логотип

CVE-2026-2920

около 2 месяцев назад

GStreamer ASF Demuxer Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the processing of stream headers within ASF files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-28843.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2026-2920

около 2 месяцев назад

GStreamer ASF Demuxer Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the processing of stream headers within ASF files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-28843.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-2920

около 2 месяцев назад

GStreamer ASF Demuxer Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the processing of stream headers within ASF files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-28843.

CVSS3: 7.8
EPSS: Низкий
debian логотип

CVE-2026-2920

около 2 месяцев назад

GStreamer ASF Demuxer Heap-based Buffer Overflow Remote Code Execution ...

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-wj6x-vgpf-cpm6

около 2 месяцев назад

GStreamer ASF Demuxer Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the processing of stream headers within ASF files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-28843.

CVSS3: 7.8
EPSS: Низкий
fstec логотип

BDU:2026-06334

3 месяца назад

Уязвимость плагина ASF мультимедийного фреймворка Gstreamer, позволяющая нарушителю выполнить произвольный код

CVSS3: 7.8
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20402-1

около 2 месяцев назад

Security update for gstreamer-plugins-ugly

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0998-1

около 2 месяцев назад

Security update for gstreamer-plugins-ugly

EPSS: Низкий
rocky логотип

RLSA-2026:6750

около 1 месяца назад

Important: gstreamer1-plugins-bad-free, gstreamer1-plugins-base, and gstreamer1-plugins-good security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-6750

около 1 месяца назад

ELSA-2026-6750: gstreamer1-plugins-bad-free, gstreamer1-plugins-base, and gstreamer1-plugins-good security update (IMPORTANT)

EPSS: Низкий
rocky логотип

RLSA-2026:6300

около 1 месяца назад

Important: gstreamer1-plugins-bad-free, gstreamer1-plugins-base, gstreamer1-plugins-good, and gstreamer1-plugins-ugly-free security update

EPSS: Низкий
rocky логотип

RLSA-2026:6259

около 1 месяца назад

Important: gstreamer1-plugins-bad-free, gstreamer1-plugins-base, gstreamer1-plugins-good, and gstreamer1-plugins-ugly-free security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-6300

около 1 месяца назад

ELSA-2026-6300: gstreamer1-plugins-bad-free, gstreamer1-plugins-base, gstreamer1-plugins-good, and gstreamer1-plugins-ugly-free security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-6259

около 1 месяца назад

ELSA-2026-6259: gstreamer1-plugins-bad-free, gstreamer1-plugins-base, gstreamer1-plugins-good, and gstreamer1-plugins-ugly-free security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-2920

GStreamer ASF Demuxer Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the processing of stream headers within ASF files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-28843.

CVSS3: 7.8
0%
Низкий
около 2 месяцев назад
redhat логотип
CVE-2026-2920

GStreamer ASF Demuxer Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the processing of stream headers within ASF files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-28843.

CVSS3: 7.8
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-2920

GStreamer ASF Demuxer Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the processing of stream headers within ASF files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-28843.

CVSS3: 7.8
0%
Низкий
около 2 месяцев назад
debian логотип
CVE-2026-2920

GStreamer ASF Demuxer Heap-based Buffer Overflow Remote Code Execution ...

CVSS3: 7.8
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-wj6x-vgpf-cpm6

GStreamer ASF Demuxer Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the processing of stream headers within ASF files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-28843.

CVSS3: 7.8
0%
Низкий
около 2 месяцев назад
fstec логотип
BDU:2026-06334

Уязвимость плагина ASF мультимедийного фреймворка Gstreamer, позволяющая нарушителю выполнить произвольный код

CVSS3: 7.8
0%
Низкий
3 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:20402-1

Security update for gstreamer-plugins-ugly

около 2 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:0998-1

Security update for gstreamer-plugins-ugly

около 2 месяцев назад
rocky логотип
RLSA-2026:6750

Important: gstreamer1-plugins-bad-free, gstreamer1-plugins-base, and gstreamer1-plugins-good security update

около 1 месяца назад
oracle-oval логотип
ELSA-2026-6750

ELSA-2026-6750: gstreamer1-plugins-bad-free, gstreamer1-plugins-base, and gstreamer1-plugins-good security update (IMPORTANT)

около 1 месяца назад
rocky логотип
RLSA-2026:6300

Important: gstreamer1-plugins-bad-free, gstreamer1-plugins-base, gstreamer1-plugins-good, and gstreamer1-plugins-ugly-free security update

около 1 месяца назад
rocky логотип
RLSA-2026:6259

Important: gstreamer1-plugins-bad-free, gstreamer1-plugins-base, gstreamer1-plugins-good, and gstreamer1-plugins-ugly-free security update

около 1 месяца назад
oracle-oval логотип
ELSA-2026-6300

ELSA-2026-6300: gstreamer1-plugins-bad-free, gstreamer1-plugins-base, gstreamer1-plugins-good, and gstreamer1-plugins-ugly-free security update (IMPORTANT)

около 1 месяца назад
oracle-oval логотип
ELSA-2026-6259

ELSA-2026-6259: gstreamer1-plugins-bad-free, gstreamer1-plugins-base, gstreamer1-plugins-good, and gstreamer1-plugins-ugly-free security update (IMPORTANT)

около 1 месяца назад

Уязвимостей на страницу