Vulnerabilities > Gstreamer
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-07-26 | CVE-2024-40897 | Out-of-bounds Write vulnerability in Gstreamer ORC Stack-based buffer overflow vulnerability exists in orcparse.c of ORC versions prior to 0.4.39. | 6.7 |
2017-01-27 | CVE-2016-9636 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstflxdec.c in the FLIC decoder in GStreamer before 1.10.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) by providing a 'write count' that goes beyond the initialized buffer. | 9.8 |
2017-01-27 | CVE-2016-9635 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstflxdec.c in the FLIC decoder in GStreamer before 1.10.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) by providing a 'skip count' that goes beyond initialized buffer. | 9.8 |
2017-01-27 | CVE-2016-9634 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstflxdec.c in the FLIC decoder in GStreamer before 1.10.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via the start_line parameter. | 9.8 |
2017-01-13 | CVE-2016-9813 | NULL Pointer Dereference vulnerability in Gstreamer 1.10.1 The _parse_pat function in the mpegts parser in GStreamer before 1.10.2 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted file. | 5.5 |
2017-01-13 | CVE-2016-9812 | Out-of-bounds Read vulnerability in Gstreamer 1.10.1 The gst_mpegts_section_new function in the mpegts decoder in GStreamer before 1.10.2 allows remote attackers to cause a denial of service (out-of-bounds read) via a too small section. | 7.5 |
2017-01-13 | CVE-2016-9811 | Out-of-bounds Read vulnerability in multiple products The windows_icon_typefind function in gst-plugins-base in GStreamer before 1.10.2, when G_SLICE is set to always-malloc, allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted ico file. | 4.7 |
2017-01-13 | CVE-2016-9810 | Out-of-bounds Read vulnerability in Gstreamer 1.10.1 The gst_decode_chain_free_internal function in the flxdex decoder in gst-plugins-good in GStreamer before 1.10.2 allows remote attackers to cause a denial of service (invalid memory read and crash) via an invalid file, which triggers an incorrect unref call. | 5.5 |
2017-01-13 | CVE-2016-9809 | Out-of-bounds Read vulnerability in Gstreamer 1.10.1 Off-by-one error in the gst_h264_parse_set_caps function in GStreamer before 1.10.2 allows remote attackers to have unspecified impact via a crafted file, which triggers an out-of-bounds read. | 7.8 |
2017-01-13 | CVE-2016-9808 | Out-of-bounds Write vulnerability in Gstreamer 1.10.1 The FLIC decoder in GStreamer before 1.10.2 allows remote attackers to cause a denial of service (out-of-bounds write and crash) via a crafted series of skip and count pairs. | 7.5 |