Vulnerabilidades en GStreamer

66 resultados
Análisis Vexday

GStreamer possui 29 vulnerabilidades catalogadas, mas nenhuma sob exploração ativa conhecida (KEV) e sem críticas de CVSS severo, reduzindo o risco imediato. A fraqueza dominante é stack-based buffer overflow (CWE-121), típica de código C/C++ legado, e apenas 2 CVEs foram publicadas nos últimos 90 dias, indicando ritmo moderado de descobertas. O risco permanece contido pelo baixo volume de exploração ativa, mas a natureza dos buffer overflows exige atenção contínua em ambientes que processam streams de origem não-confiável.

CVE-2023-44429HIGHGStreamer AV1 Codec Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 2.2%CVE-2023-37328HIGHGStreamer PGS File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 2.1%CVE-2023-40476HIGHGStreamer H265 Parsing Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 2.0%CVE-2023-40475HIGHGStreamer MXF File Parsing Integer Overflow Remote Code Execution VulnerabilityEPSS 1.9%CVE-2023-40474HIGHGStreamer MXF File Parsing Integer Overflow Remote Code Execution VulnerabilityEPSS 1.9%CVE-2023-44446HIGHGStreamer MXF File Parsing Use-After-Free Remote Code Execution VulnerabilityEPSS 1.7%CVE-2023-37327HIGHGStreamer FLAC File Parsing Integer Overflow Remote Code Execution VulnerabilityEPSS 1.7%CVE-2023-37329HIGHGStreamer SRT File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 1.6%CVE-2024-0444HIGHGStreamer AV1 Video Parsing Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 1.6%CVE-2024-4453HIGHGStreamer EXIF Metadata Parsing Integer Overflow Remote Code Execution VulnerabilityEPSS 1.6%CVE-2023-50186HIGHGStreamer AV1 Video Parsing Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 1.5%CVE-2023-38103HIGHGStreamer RealMedia File Parsing Integer Overflow Remote Code Execution VulnerabilityEPSS 1.5%CVE-2023-38104HIGHGStreamer RealMedia File Parsing Integer Overflow Remote Code Execution VulnerabilityEPSS 1.4%CVE-2024-47606HIGHGHSL-2024-166: GStreamer Integer overflows in MP4/MOV demuxer and memory allocator that can lead to out-of-bounds writesEPSS 1.4%CVE-2024-47541MEDIUMGHSL-2024-228: GStreamer has an out-of-bounds write in SSA subtitle parserEPSS 1.3%CVE-2024-47539HIGHGHSL-2024-195: GStreamer has an OOB-write in convert_to_s334_1aEPSS 1.3%CVE-2024-47538HIGHGHSL-2024-115: GStreamer has a stack-buffer overflow in vorbis_handle_identification_packetEPSS 1.3%CVE-2024-47607HIGHGHSL-2024-116: Stack-buffer overflow in gst_opus_dec_parse_headerEPSS 1.2%CVE-2024-47775MEDIUMGHSL-2024-261: GStreamer has an OOB-read in parse_ds64EPSS 1.2%CVE-2024-47597MEDIUMGHSL-2024-245: GStreamer has an OOB-read in qtdemux_parse_samplesEPSS 1.2%