Vulnerabilities > Gstreamer Project > Gstreamer > High

DATE CVE VULNERABILITY TITLE RISK
2017-01-23 CVE-2016-9447 Out-of-bounds Write vulnerability in Gstreamer Project Gstreamer
The ROM mappings in the NSF decoder in gstreamer 0.10.x allow remote attackers to cause a denial of service (out-of-bounds read or write) and possibly execute arbitrary code via a crafted NSF music file.
local
low complexity
gstreamer-project CWE-787
7.8
2017-01-23 CVE-2016-9446 Improper Initialization vulnerability in multiple products
The vmnc decoder in the gstreamer does not initialize the render canvas, which allows remote attackers to obtain sensitive information as demonstrated by thumbnailing a simple 1 frame vmnc movie that does not draw to the allocated render canvas.
7.5
2017-01-23 CVE-2016-9445 Integer Overflow or Wraparound vulnerability in Gstreamer Project Gstreamer 1.10.0
Integer overflow in the vmnc decoder in the gstreamer allows remote attackers to cause a denial of service (crash) via large width and height values, which triggers a buffer overflow.
network
low complexity
gstreamer-project CWE-190
7.5