<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – GStreamer (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/gstreamer.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/gstreamer-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – GStreamer (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:45 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-3086 – GStreamer H.266 Codec Parser Out-Of-Bounds Write Remote Code Execution Vulnerabi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3086</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3086</guid>
    <pubDate>Mon, 16 Mar 2026 14:19:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-3086</strong></p>
  <p>GStreamer H.266 Codec Parser Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation.  The specific flaw exists within the processing of APS units. The issue…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3086">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-3085 – GStreamer rtpqdm2depay Heap-based Buffer Overflow Remote Code Execution Vulnerab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3085</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3085</guid>
    <pubDate>Mon, 16 Mar 2026 14:19:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-3085</strong></p>
  <p>GStreamer rtpqdm2depay Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation.  The specific flaw exists within the processing of X-QDM RTP payloads.…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3085">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-3084 – GStreamer H.266 Codec Parser Integer Underflow Remote Code Execution Vulnerabili...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3084</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3084</guid>
    <pubDate>Mon, 16 Mar 2026 14:19:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-3084</strong></p>
  <p>GStreamer H.266 Codec Parser Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation.  The specific flaw exists within the parsing of picture partitions. The i…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-191</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3084">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-3083 – GStreamer rtpqdm2depay Out-Of-Bounds Write Remote Code Execution Vulnerability. ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3083</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3083</guid>
    <pubDate>Mon, 16 Mar 2026 14:19:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-3083</strong></p>
  <p>GStreamer rtpqdm2depay Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation.  The specific flaw exists within the processing of X-QDM RTP payload elements…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-129</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3083">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-3082 – GStreamer JPEG Parser Heap-based Buffer Overflow Remote Code Execution Vulnerabi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3082</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3082</guid>
    <pubDate>Mon, 16 Mar 2026 14:19:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-3082</strong></p>
  <p>GStreamer JPEG Parser Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation.  The specific flaw exists within the processing of Huffman tables. The…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3082">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-3081 – GStreamer H.266 Codec Parser Stack-based Buffer Overflow Remote Code Execution V...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3081</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3081</guid>
    <pubDate>Mon, 16 Mar 2026 14:19:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-3081</strong></p>
  <p>GStreamer H.266 Codec Parser Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation.  The specific flaw exists within the parsing of decoding units.…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3081">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-2923 – GStreamer DVB Subtitles Out-Of-Bounds Write Remote Code Execution Vulnerability...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2923</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2923</guid>
    <pubDate>Mon, 16 Mar 2026 14:19:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-2923</strong></p>
  <p>GStreamer DVB Subtitles Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation.  The specific flaw exists within the handling of coordinates. The issue resu…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2923">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-2922 – GStreamer RealMedia Demuxer Out-Of-Bounds Write Remote Code Execution Vulnerabil...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2922</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2922</guid>
    <pubDate>Mon, 16 Mar 2026 14:19:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-2922</strong></p>
  <p>GStreamer RealMedia Demuxer Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation.  The specific flaw exists within the processing of video packets. The is…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2922">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-2921 – GStreamer RIFF Palette Integer Overflow Remote Code Execution Vulnerability. Thi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2921</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2921</guid>
    <pubDate>Mon, 16 Mar 2026 14:19:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-2921</strong></p>
  <p>GStreamer RIFF Palette Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation.  The specific flaw exists within the handling of palette data in AVI files. The…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2921">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-2920 – GStreamer ASF Demuxer Heap-based Buffer Overflow Remote Code Execution Vulnerabi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2920</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2920</guid>
    <pubDate>Mon, 16 Mar 2026 14:19:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-2920</strong></p>
  <p>GStreamer ASF Demuxer Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation.  The specific flaw exists within the processing of stream headers withi…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2920">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-47219 – In GStreamer through 1.26.1, the isomp4 plugin's qtdemux_parse_trak function may...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-47219</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-47219</guid>
    <pubDate>Thu, 07 Aug 2025 20:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-47219</strong></p>
  <p>In GStreamer through 1.26.1, the isomp4 plugin's qtdemux_parse_trak function may read past the end of a heap buffer while parsing an MP4 file, possibly leading to information disclosure.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47219">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-6663 – GStreamer H266 Codec Parsing Stack-based Buffer Overflow Remote Code Execution V...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-6663</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-6663</guid>
    <pubDate>Mon, 07 Jul 2025 15:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-6663</strong></p>
  <p>GStreamer H266 Codec Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation.  The specific flaw exists within the parsing of H266 sei messag…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-6663">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-3887 – GStreamer H265 Codec Parsing Stack-based Buffer Overflow Remote Code Execution V...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-3887</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-3887</guid>
    <pubDate>Thu, 22 May 2025 01:15:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-3887</strong></p>
  <p>GStreamer H265 Codec Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation.  The specific flaw exists within the parsing of H265 slice head…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-3887">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-2759 – GStreamer Incorrect Permission Assignment Local Privilege Escalation Vulnerabili...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-2759</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-2759</guid>
    <pubDate>Thu, 22 May 2025 01:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-2759</strong></p>
  <p>GStreamer Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of GStreamer. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.  The specific flaw exists within the product installer. The issue results fr…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-2759">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-47835 – GStreamer is a library for constructing graphs of media-handling components. A n...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47835</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47835</guid>
    <pubDate>Thu, 12 Dec 2024 02:03:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-47835</strong></p>
  <p>GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference vulnerability has been detected in the parse_lrc function within gstsubparse.c. The parse_lrc function calls strchr() to find the character ']' in the string line. The pointer returned by this call is then passed to g_strdup(). However, if the string line does not contain the character ']', str…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47835">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-47834 – GStreamer is a library for constructing graphs of media-handling components. An ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47834</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47834</guid>
    <pubDate>Thu, 12 Dec 2024 02:03:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-47834</strong></p>
  <p>GStreamer is a library for constructing graphs of media-handling components. An Use-After-Free read vulnerability has been discovered affecting the processing of CodecPrivate elements in Matroska streams. In the GST_MATROSKA_ID_CODECPRIVATE case within the gst_matroska_demux_parse_stream function, a data chunk is allocated using gst_ebml_read_binary. Later, the allocated memory is freed in the gs…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47834">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-47778 – GStreamer is a library for constructing graphs of media-handling components. An ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47778</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47778</guid>
    <pubDate>Thu, 12 Dec 2024 02:03:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-47778</strong></p>
  <p>GStreamer is a library for constructing graphs of media-handling components. An OOB-read vulnerability has been discovered in gst_wavparse_adtl_chunk within gstwavparse.c. This vulnerability arises due to insufficient validation of the size parameter, which can exceed the bounds of the data buffer. As a result, an OOB read occurs in the following while loop. This vulnerability can result in readi…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47778">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-47777 – GStreamer is a library for constructing graphs of media-handling components. An ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47777</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47777</guid>
    <pubDate>Thu, 12 Dec 2024 02:03:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-47777</strong></p>
  <p>GStreamer is a library for constructing graphs of media-handling components. An OOB-read vulnerability has been identified in the gst_wavparse_smpl_chunk function within gstwavparse.c. This function attempts to read 4 bytes from the data + 12 offset without checking if the size of the data buffer is sufficient. If the buffer is too small, the function reads beyond its bounds. This vulnerability m…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47777">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-47776 – GStreamer is a library for constructing graphs of media-handling components. An ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47776</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47776</guid>
    <pubDate>Thu, 12 Dec 2024 02:03:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-47776</strong></p>
  <p>GStreamer is a library for constructing graphs of media-handling components. An OOB-read has been discovered in gst_wavparse_cue_chunk within gstwavparse.c. The vulnerability happens due to a discrepancy between the size of the data buffer and the size value provided to the function. This mismatch causes the comparison  if (size < 4 + ncues * 24) to fail in some cases, allowing the subsequent loo…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47776">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-47775 – GStreamer is a library for constructing graphs of media-handling components. An ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47775</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47775</guid>
    <pubDate>Thu, 12 Dec 2024 02:03:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-47775</strong></p>
  <p>GStreamer is a library for constructing graphs of media-handling components. An OOB-read vulnerability has been found in the parse_ds64 function within gstwavparse.c. The parse_ds64 function does not check that the buffer buf contains sufficient data before attempting to read from it, doing multiple GST_READ_UINT32_LE operations without performing boundary checks. This can lead to an OOB-read whe…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47775">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-47774 – GStreamer is a library for constructing graphs of media-handling components. An ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47774</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47774</guid>
    <pubDate>Thu, 12 Dec 2024 02:03:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-47774</strong></p>
  <p>GStreamer is a library for constructing graphs of media-handling components. An OOB-read vulnerability has been identified in the gst_avi_subtitle_parse_gab2_chunk function within gstavisubtitle.c. The function reads the name_length value directly from the input file without checking it properly. Then, the a condition, does not properly handle cases where name_length is greater than 0xFFFFFFFF -…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47774">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-47615 – GStreamer is a library for constructing graphs of media-handling components. An ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47615</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47615</guid>
    <pubDate>Thu, 12 Dec 2024 02:03:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-47615</strong></p>
  <p>GStreamer is a library for constructing graphs of media-handling components. An OOB-Write has been detected in the function gst_parse_vorbis_setup_packet within vorbis_parse.c. The integer size is read from the input file without proper validation. As a result, size can exceed the fixed size of the pad->vorbis_mode_sizes array (which size is 256). When this happens, the for loop overwrites the en…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47615">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-47613 – GStreamer is a library for constructing graphs of media-handling components. A n...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47613</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47613</guid>
    <pubDate>Thu, 12 Dec 2024 02:03:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-47613</strong></p>
  <p>GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference vulnerability has been identified in `gst_gdk_pixbuf_dec_flush` within `gstgdkpixbufdec.c`. This function invokes `memcpy`, using `out_pix` as the destination address. `out_pix` is expected to point to the frame 0 from the frame structure, which is read from the input file. However, in certain…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47613">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-47607 – GStreamer is a library for constructing graphs of media-handling components.  st...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47607</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47607</guid>
    <pubDate>Thu, 12 Dec 2024 02:03:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-47607</strong></p>
  <p>GStreamer is a library for constructing graphs of media-handling components.  stack-buffer overflow has been detected in the gst_opus_dec_parse_header function within `gstopusdec.c'. The pos array is a stack-allocated buffer of size 64. If n_channels exceeds 64, the for loop will write beyond the boundaries of the pos array. The value written will always be GST_AUDIO_CHANNEL_POSITION_NONE. This b…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47607">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-47606 – GStreamer is a library for constructing graphs of media-handling components. An ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47606</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47606</guid>
    <pubDate>Thu, 12 Dec 2024 02:03:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-47606</strong></p>
  <p>GStreamer is a library for constructing graphs of media-handling components. An integer underflow has been detected in the function qtdemux_parse_theora_extension within qtdemux.c. The vulnerability occurs due to an underflow of the gint size variable, which causes size to hold a large unintended value when cast to an unsigned integer. This 32-bit negative value is then cast to a 64-bit unsigned…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47606">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-47603 – GStreamer is a library for constructing graphs of media-handling components. A n...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47603</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47603</guid>
    <pubDate>Thu, 12 Dec 2024 02:03:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-47603</strong></p>
  <p>GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference vulnerability has been discovered in the gst_matroska_demux_update_tracks function within matroska-demux.c. The vulnerability occurs when the gst_caps_is_equal function is called with invalid caps values. If this happen, then in the function gst_buffer_get_size the call to GST_BUFFER_MEM_PTR ca…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47603">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-47602 – GStreamer is a library for constructing graphs of media-handling components. A n...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47602</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47602</guid>
    <pubDate>Thu, 12 Dec 2024 02:03:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-47602</strong></p>
  <p>GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference vulnerability has been discovered in the gst_matroska_demux_add_wvpk_header function within matroska-demux.c. This function does not properly check the validity of the stream->codec_priv pointer in the following code. If stream->codec_priv is NULL, the call to GST_READ_UINT16_LE will attempt to…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47602">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-47601 – GStreamer is a library for constructing graphs of media-handling components. A n...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47601</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47601</guid>
    <pubDate>Thu, 12 Dec 2024 02:03:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-47601</strong></p>
  <p>GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference vulnerability has been discovered in the gst_matroska_demux_parse_blockgroup_or_simpleblock function within matroska-demux.c. This function does not properly check the validity of the GstBuffer *sub pointer before performing dereferences. As a result, null pointer dereferences may occur. This v…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47601">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-47600 – GStreamer is a library for constructing graphs of media-handling components. An ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47600</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47600</guid>
    <pubDate>Thu, 12 Dec 2024 02:03:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-47600</strong></p>
  <p>GStreamer is a library for constructing graphs of media-handling components. An OOB-read vulnerability has been detected in the format_channel_mask function in gst-discoverer.c. The vulnerability affects the local array position, which is defined with a fixed size of 64 elements. However, the function gst_discoverer_audio_info_get_channels may return a guint channels value greater than 64. This c…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47600">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-47599 – GStreamer is a library for constructing graphs of media-handling components. A n...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47599</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47599</guid>
    <pubDate>Thu, 12 Dec 2024 02:03:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-47599</strong></p>
  <p>GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference vulnerability has been discovered in the gst_jpeg_dec_negotiate function in gstjpegdec.c. This function does not check for a NULL return value from gst_video_decoder_set_output_state. When this happens, dereferences of the outstate pointer will lead to a null pointer dereference. This vulnerabi…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47599">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-47598 – GStreamer is a library for constructing graphs of media-handling components. An ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47598</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47598</guid>
    <pubDate>Thu, 12 Dec 2024 02:03:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-47598</strong></p>
  <p>GStreamer is a library for constructing graphs of media-handling components. An OOB-read vulnerability has been discovered in the qtdemux_merge_sample_table function within qtdemux.c. The problem is that the size of the stts buffer isn’t properly checked before reading stts_duration, allowing the program to read 4 bytes beyond the boundaries of stts->data. This vulnerability reads up to 4 bytes p…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47598">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-47597 – GStreamer is a library for constructing graphs of media-handling components. An ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47597</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47597</guid>
    <pubDate>Thu, 12 Dec 2024 02:03:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-47597</strong></p>
  <p>GStreamer is a library for constructing graphs of media-handling components. An OOB-read has been detected in the function qtdemux_parse_samples within qtdemux.c. This issue arises when the function qtdemux_parse_samples reads data beyond the boundaries of the stream->stco buffer. The following code snippet shows the call to qt_atom_parser_get_offset_unchecked, which leads to the OOB-read when pa…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47597">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-47596 – GStreamer is a library for constructing graphs of media-handling components. An ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47596</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47596</guid>
    <pubDate>Thu, 12 Dec 2024 02:03:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-47596</strong></p>
  <p>GStreamer is a library for constructing graphs of media-handling components. An OOB-read has been discovered in the qtdemux_parse_svq3_stsd_data function within qtdemux.c. In the FOURCC_SMI_ case, seqh_size is read from the input file without proper validation. If seqh_size is greater than the remaining size of the data buffer, it can lead to an OOB-read in the following call to gst_buffer_fill,…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47596">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-47546 – GStreamer is a library for constructing graphs of media-handling components. An ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47546</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47546</guid>
    <pubDate>Thu, 12 Dec 2024 02:03:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-47546</strong></p>
  <p>GStreamer is a library for constructing graphs of media-handling components. An integer underflow has been detected in extract_cc_from_data function within qtdemux.c. In the FOURCC_c708 case, the subtraction atom_length - 8 may result in an underflow if atom_length is less than 8. When that subtraction underflows, *cclen ends up being a large number, and then cclen is passed to g_memdup2 leading…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-191</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47546">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-47545 – GStreamer is a library for constructing graphs of media-handling components. An ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47545</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47545</guid>
    <pubDate>Thu, 12 Dec 2024 02:03:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-47545</strong></p>
  <p>GStreamer is a library for constructing graphs of media-handling components. An integer underflow has been detected in qtdemux_parse_trak function within qtdemux.c. During the strf parsing case, the subtraction size -= 40 can lead to a negative integer overflow if it is less than 40. If this happens, the subsequent call to gst_buffer_fill will invoke memcpy with a large tocopy size, resulting in…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-191</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47545">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-47544 – GStreamer is a library for constructing graphs of media-handling components. The...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47544</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47544</guid>
    <pubDate>Thu, 12 Dec 2024 02:03:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-47544</strong></p>
  <p>GStreamer is a library for constructing graphs of media-handling components. The function qtdemux_parse_sbgp in qtdemux.c is affected by a null dereference vulnerability. This vulnerability is fixed in 1.24.10.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47544">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-47543 – GStreamer is a library for constructing graphs of media-handling components. An ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47543</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47543</guid>
    <pubDate>Thu, 12 Dec 2024 02:03:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-47543</strong></p>
  <p>GStreamer is a library for constructing graphs of media-handling components. An OOB-read vulnerability has been discovered in qtdemux_parse_container function within qtdemux.c. In the parent function qtdemux_parse_node, the value of length is not well checked. So, if length is big enough, it causes the pointer end to point beyond the boundaries of buffer. Subsequently, in the qtdemux_parse_contai…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47543">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-47542 – GStreamer is a library for constructing graphs of media-handling components. A n...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47542</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47542</guid>
    <pubDate>Thu, 12 Dec 2024 02:03:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-47542</strong></p>
  <p>GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference has been discovered in the id3v2_read_synch_uint function, located in id3v2.c. If id3v2_read_synch_uint is called with a null work->hdr.frame_data, the pointer guint8 *data is accessed without validation, resulting in a null pointer dereference. This vulnerability can result in a Denial of Serv…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47542">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-47541 – GStreamer is a library for constructing graphs of media-handling components. An ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47541</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47541</guid>
    <pubDate>Thu, 12 Dec 2024 02:03:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-47541</strong></p>
  <p>GStreamer is a library for constructing graphs of media-handling components. An OOB-write vulnerability has been identified in the gst_ssa_parse_remove_override_codes function of the gstssaparse.c file. This function is responsible for parsing and removing SSA (SubStation Alpha) style override codes, which are enclosed in curly brackets ({}). The issue arises when a closing curly bracket "}" appe…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47541">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-47540 – GStreamer is a library for constructing graphs of media-handling components. An ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47540</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47540</guid>
    <pubDate>Thu, 12 Dec 2024 02:03:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-47540</strong></p>
  <p>GStreamer is a library for constructing graphs of media-handling components. An uninitialized stack variable vulnerability has been identified in the gst_matroska_demux_add_wvpk_header function within matroska-demux.c. When size < 4, the program calls gst_buffer_unmap with an uninitialized map variable. Then, in the gst_memory_unmap function, the program will attempt to unmap the buffer using the…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-457</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47540">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-47539 – GStreamer is a library for constructing graphs of media-handling components. An ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47539</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47539</guid>
    <pubDate>Thu, 12 Dec 2024 02:03:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-47539</strong></p>
  <p>GStreamer is a library for constructing graphs of media-handling components. An out-of-bounds write vulnerability was identified in the convert_to_s334_1a function in isomp4/qtdemux.c. The vulnerability arises due to a discrepancy between the size of memory allocated to the storage array and the loop condition i * 2 < ccpair_size. Specifically, when ccpair_size is even, the allocated size in stor…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47539">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-47538 – GStreamer is a library for constructing graphs of media-handling components. A s...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47538</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47538</guid>
    <pubDate>Thu, 12 Dec 2024 02:03:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-47538</strong></p>
  <p>GStreamer is a library for constructing graphs of media-handling components. A stack-buffer overflow has been detected in the `vorbis_handle_identification_packet` function within `gstvorbisdec.c`. The position array is a stack-allocated buffer of size 64. If vd->vi.channels exceeds 64, the for loop will write beyond the boundaries of the position array. The value written will always be `GST_AUDI…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47538">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-47537 – GStreamer is a library for constructing graphs of media-handling components. The...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47537</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47537</guid>
    <pubDate>Thu, 12 Dec 2024 02:03:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-47537</strong></p>
  <p>GStreamer is a library for constructing graphs of media-handling components. The program attempts to reallocate the memory pointed to by stream->samples to accommodate stream->n_samples + samples_count elements of type QtDemuxSample. The problem is that samples_count is read from the input file. And if this value is big enough, this can lead to an integer overflow during the addition. As a conseq…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47537">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-44331 – Incorrect Access Control in GStreamer RTSP server 1.25.0 in gst-rtsp-server/rtsp...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-44331</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-44331</guid>
    <pubDate>Tue, 22 Oct 2024 22:15:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-44331</strong></p>
  <p>Incorrect Access Control in GStreamer RTSP server 1.25.0 in gst-rtsp-server/rtsp-media.c allows remote attackers to cause a denial of service via a series of specially crafted hexstream requests.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-44331">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-0444 – GStreamer AV1 Video Parsing Stack-based Buffer Overflow Remote Code Execution Vu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-0444</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-0444</guid>
    <pubDate>Fri, 07 Jun 2024 23:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-0444</strong></p>
  <p>GStreamer AV1 Video Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation.  The specific flaw exists within the parsing of tile list data w…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-0444">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-4453 – GStreamer EXIF Metadata Parsing Integer Overflow Remote Code Execution Vulnerabi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-4453</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-4453</guid>
    <pubDate>Wed, 22 May 2024 20:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-4453</strong></p>
  <p>GStreamer EXIF Metadata Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation.  The specific flaw exists within the parsing of EXIF metadata. The issu…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-4453">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-50186 – GStreamer AV1 Video Parsing Stack-based Buffer Overflow Remote Code Execution Vu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-50186</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-50186</guid>
    <pubDate>Fri, 03 May 2024 03:16:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-50186</strong></p>
  <p>GStreamer AV1 Video Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation.  The specific flaw exists within the parsing of metadata within…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-50186">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-44446 – GStreamer MXF File Parsing Use-After-Free Remote Code Execution Vulnerability. T...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-44446</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-44446</guid>
    <pubDate>Fri, 03 May 2024 03:16:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-44446</strong></p>
  <p>GStreamer MXF File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation.  The specific flaw exists within the parsing of MXF video files. The issue res…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-44446">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-44429 – GStreamer AV1 Codec Parsing Heap-based Buffer Overflow Remote Code Execution Vul...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-44429</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-44429</guid>
    <pubDate>Fri, 03 May 2024 03:15:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-44429</strong></p>
  <p>GStreamer AV1 Codec Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation.  The specific flaw exists within the parsing of AV1 encoded video…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-44429">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-40476 – GStreamer H265 Parsing Stack-based Buffer Overflow Remote Code Execution Vulnera...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-40476</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-40476</guid>
    <pubDate>Fri, 03 May 2024 03:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-40476</strong></p>
  <p>GStreamer H265 Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation.  The specific flaw exists within the parsing of H265 encoded video fi…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-40476">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-40475 – GStreamer MXF File Parsing Integer Overflow Remote Code Execution Vulnerability...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-40475</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-40475</guid>
    <pubDate>Fri, 03 May 2024 03:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-40475</strong></p>
  <p>GStreamer MXF File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation.  The specific flaw exists within the parsing of MXF video files. The issue r…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-40475">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-40474 – GStreamer MXF File Parsing Integer Overflow Remote Code Execution Vulnerability...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-40474</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-40474</guid>
    <pubDate>Fri, 03 May 2024 03:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-40474</strong></p>
  <p>GStreamer MXF File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation.  The specific flaw exists within the parsing of MXF video files. The issue r…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-40474">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-38104 – GStreamer RealMedia File Parsing Integer Overflow Remote Code Execution Vulnerab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-38104</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-38104</guid>
    <pubDate>Fri, 03 May 2024 02:15:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-38104</strong></p>
  <p>GStreamer RealMedia File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation.  The specific flaw exists within the parsing of MDPR chunks. The issue…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-38104">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-38103 – GStreamer RealMedia File Parsing Integer Overflow Remote Code Execution Vulnerab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-38103</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-38103</guid>
    <pubDate>Fri, 03 May 2024 02:15:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-38103</strong></p>
  <p>GStreamer RealMedia File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation.  The specific flaw exists within the parsing of MDPR chunks. The issue…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-38103">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-37329 – GStreamer SRT File Parsing Heap-based Buffer Overflow Remote Code Execution Vuln...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-37329</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-37329</guid>
    <pubDate>Fri, 03 May 2024 02:15:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-37329</strong></p>
  <p>GStreamer SRT File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation.  The specific flaw exists within the parsing of SRT subtitle files…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-37329">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-37328 – GStreamer PGS File Parsing Heap-based Buffer Overflow Remote Code Execution Vuln...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-37328</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-37328</guid>
    <pubDate>Fri, 03 May 2024 02:15:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-37328</strong></p>
  <p>GStreamer PGS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation.  The specific flaw exists within the parsing of PGS subtitle files…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-37328">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-37327 – GStreamer FLAC File Parsing Integer Overflow Remote Code Execution Vulnerability...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-37327</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-37327</guid>
    <pubDate>Fri, 03 May 2024 02:15:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-37327</strong></p>
  <p>GStreamer FLAC File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation.  The specific flaw exists within the parsing of FLAC audio files. The issue…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-37327">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-6185 – Improper Input Validation vulnerability in GStreamer integration of The Document...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-6185</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-6185</guid>
    <pubDate>Mon, 11 Dec 2023 12:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-6185</strong></p>
  <p>Improper Input Validation vulnerability in GStreamer integration of The Document Foundation LibreOffice allows an attacker to execute arbitrary GStreamer plugins.  In affected versions the filename of the embedded video is not sufficiently escaped when passed to GStreamer enabling an attacker to run arbitrary gstreamer plugins depending on what plugins are installed on the target system.</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-6185">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-3498 – GStreamer before 1.18.4 might cause heap corruption when parsing certain malform...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-3498</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-3498</guid>
    <pubDate>Mon, 19 Apr 2021 21:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-3498</strong></p>
  <p>GStreamer before 1.18.4 might cause heap corruption when parsing certain malformed Matroska files.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-3498">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-3497 – GStreamer before 1.18.4 might access already-freed memory in error code paths wh...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-3497</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-3497</guid>
    <pubDate>Mon, 19 Apr 2021 21:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-3497</strong></p>
  <p>GStreamer before 1.18.4 might access already-freed memory in error code paths when demuxing certain malformed Matroska files.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-3497">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-3185 – A flaw was found in the gstreamer h264 component of gst-plugins-bad before v1.18...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-3185</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-3185</guid>
    <pubDate>Tue, 26 Jan 2021 18:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-3185</strong></p>
  <p>A flaw was found in the gstreamer h264 component of gst-plugins-bad before v1.18.1 where when parsing a h264 header, an attacker could cause the stack to be smashed, memory corruption and possibly code execution.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-3185">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-6095 – An exploitable denial of service vulnerability exists in the GstRTSPAuth functio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-6095</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-6095</guid>
    <pubDate>Fri, 27 Mar 2020 20:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-6095</strong></p>
  <p>An exploitable denial of service vulnerability exists in the GstRTSPAuth functionality of GStreamer/gst-rtsp-server 1.14.5. A specially crafted RTSP setup request can cause a null pointer deference resulting in denial-of-service. An attacker can send a malicious packet to trigger this vulnerability.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-690</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-6095">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-9928 – GStreamer before 1.16.0 has a heap-based buffer overflow in the RTSP connection ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-9928</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-9928</guid>
    <pubDate>Wed, 24 Apr 2019 15:29:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-9928</strong></p>
  <p>GStreamer before 1.16.0 has a heap-based buffer overflow in the RTSP connection parser via a crafted response from a server, potentially allowing remote code execution.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-9928">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-5848 – The gst_ps_demux_parse_psm function in gst/mpegdemux/gstmpegdemux.c in gst-plugi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-5848</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-5848</guid>
    <pubDate>Thu, 09 Feb 2017 15:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-5848</strong></p>
  <p>The gst_ps_demux_parse_psm function in gst/mpegdemux/gstmpegdemux.c in gst-plugins-bad in GStreamer allows remote attackers to cause a denial of service (invalid memory read and crash) via vectors involving PSM parsing.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-5848">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-5847 – The gst_asf_demux_process_ext_content_desc function in gst/asfdemux/gstasfdemux...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-5847</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-5847</guid>
    <pubDate>Thu, 09 Feb 2017 15:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-5847</strong></p>
  <p>The gst_asf_demux_process_ext_content_desc function in gst/asfdemux/gstasfdemux.c in gst-plugins-ugly in GStreamer allows remote attackers to cause a denial of service (out-of-bounds heap read) via vectors involving extended content descriptors.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-5847">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-5845 – The gst_avi_demux_parse_ncdt function in gst/avi/gstavidemux.c in gst-plugins-go...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-5845</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-5845</guid>
    <pubDate>Thu, 09 Feb 2017 15:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-5845</strong></p>
  <p>The gst_avi_demux_parse_ncdt function in gst/avi/gstavidemux.c in gst-plugins-good in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (invalid memory read and crash) via a ncdt sub-tag that "goes behind" the surrounding tag.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-5845">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-5843 – Multiple use-after-free vulnerabilities in the (1) gst_mini_object_unref, (2) gs...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-5843</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-5843</guid>
    <pubDate>Thu, 09 Feb 2017 15:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-5843</strong></p>
  <p>Multiple use-after-free vulnerabilities in the (1) gst_mini_object_unref, (2) gst_tag_list_unref, and (3) gst_mxf_demux_update_essence_tracks functions in GStreamer before 1.10.3 allow remote attackers to cause a denial of service (crash) via vectors involving stream tags, as demonstrated by 02785736.mxf.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-5843">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-5841 – The gst_avi_demux_parse_ncdt function in gst/avi/gstavidemux.c in gst-plugins-go...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-5841</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-5841</guid>
    <pubDate>Thu, 09 Feb 2017 15:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-5841</strong></p>
  <p>The gst_avi_demux_parse_ncdt function in gst/avi/gstavidemux.c in gst-plugins-good in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (out-of-bounds heap read) via vectors involving ncdt tags.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-5841">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-5840 – The qtdemux_parse_samples function in gst/isomp4/qtdemux.c in gst-plugins-good i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-5840</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-5840</guid>
    <pubDate>Thu, 09 Feb 2017 15:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-5840</strong></p>
  <p>The qtdemux_parse_samples function in gst/isomp4/qtdemux.c in gst-plugins-good in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (out-of-bounds heap read) via vectors involving the current stts index.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-5840">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-5839 – The gst_riff_create_audio_caps function in gst-libs/gst/riff/riff-media.c in gst...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-5839</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-5839</guid>
    <pubDate>Thu, 09 Feb 2017 15:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-5839</strong></p>
  <p>The gst_riff_create_audio_caps function in gst-libs/gst/riff/riff-media.c in gst-plugins-base in GStreamer before 1.10.3 does not properly limit recursion, which allows remote attackers to cause a denial of service (stack overflow and crash) via vectors involving nested WAVEFORMATEX.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-674</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-5839">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-5838 – The gst_date_time_new_from_iso8601_string function in gst/gstdatetime.c in GStre...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-5838</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-5838</guid>
    <pubDate>Thu, 09 Feb 2017 15:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-5838</strong></p>
  <p>The gst_date_time_new_from_iso8601_string function in gst/gstdatetime.c in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a malformed datetime string.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-5838">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-10199 – The qtdemux_tag_add_str_full function in gst/isomp4/qtdemux.c in gst-plugins-goo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-10199</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-10199</guid>
    <pubDate>Thu, 09 Feb 2017 15:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-10199</strong></p>
  <p>The qtdemux_tag_add_str_full function in gst/isomp4/qtdemux.c in gst-plugins-good in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted tag value.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-10199">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2016-9636 – Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstfl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-9636</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-9636</guid>
    <pubDate>Fri, 27 Jan 2017 22:59:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2016-9636</strong></p>
  <p>Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstflxdec.c in the FLIC decoder in GStreamer before 1.10.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) by providing a 'write count' that goes beyond the initialized buffer.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-9636">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2016-9635 – Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstfl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-9635</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-9635</guid>
    <pubDate>Fri, 27 Jan 2017 22:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2016-9635</strong></p>
  <p>Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstflxdec.c in the FLIC decoder in GStreamer before 1.10.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) by providing a 'skip count' that goes beyond initialized buffer.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-9635">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2016-9634 – Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstfl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-9634</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-9634</guid>
    <pubDate>Fri, 27 Jan 2017 22:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2016-9634</strong></p>
  <p>Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstflxdec.c in the FLIC decoder in GStreamer before 1.10.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via the start_line parameter.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-9634">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-9447 – The ROM mappings in the NSF decoder in gstreamer 0.10.x allow remote attackers t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-9447</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-9447</guid>
    <pubDate>Mon, 23 Jan 2017 21:59:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-9447</strong></p>
  <p>The ROM mappings in the NSF decoder in gstreamer 0.10.x allow remote attackers to cause a denial of service (out-of-bounds read or write) and possibly execute arbitrary code via a crafted NSF music file.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-9447">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-9446 – The vmnc decoder in the gstreamer does not initialize the render canvas, which a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-9446</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-9446</guid>
    <pubDate>Mon, 23 Jan 2017 21:59:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-9446</strong></p>
  <p>The vmnc decoder in the gstreamer does not initialize the render canvas, which allows remote attackers to obtain sensitive information as demonstrated by thumbnailing a simple 1 frame vmnc movie that does not draw to the allocated render canvas.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-665</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-9446">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-9445 – Integer overflow in the vmnc decoder in the gstreamer allows remote attackers to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-9445</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-9445</guid>
    <pubDate>Mon, 23 Jan 2017 21:59:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-9445</strong></p>
  <p>Integer overflow in the vmnc decoder in the gstreamer allows remote attackers to cause a denial of service (crash) via large width and height values, which triggers a buffer overflow.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-9445">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-9812 – The gst_mpegts_section_new function in the mpegts decoder in GStreamer before 1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-9812</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-9812</guid>
    <pubDate>Fri, 13 Jan 2017 16:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-9812</strong></p>
  <p>The gst_mpegts_section_new function in the mpegts decoder in GStreamer before 1.10.2 allows remote attackers to cause a denial of service (out-of-bounds read) via a too small section.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-9812">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-9809 – Off-by-one error in the gst_h264_parse_set_caps function in GStreamer before 1.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-9809</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-9809</guid>
    <pubDate>Fri, 13 Jan 2017 16:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-9809</strong></p>
  <p>Off-by-one error in the gst_h264_parse_set_caps function in GStreamer before 1.10.2 allows remote attackers to have unspecified impact via a crafted file, which triggers an out-of-bounds read.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-9809">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-9808 – The FLIC decoder in GStreamer before 1.10.2 allows remote attackers to cause a d...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-9808</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-9808</guid>
    <pubDate>Fri, 13 Jan 2017 16:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-9808</strong></p>
  <p>The FLIC decoder in GStreamer before 1.10.2 allows remote attackers to cause a denial of service (out-of-bounds write and crash) via a crafted series of skip and count pairs.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-9808">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2014-8154 – The Gst.MapInfo function in Vala 0.26.0 and 0.26.1 uses an incorrect buffer leng...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-8154</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-8154</guid>
    <pubDate>Tue, 27 Jan 2015 20:59:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2014-8154</strong></p>
  <p>The Gst.MapInfo function in Vala 0.26.0 and 0.26.1 uses an incorrect buffer length declaration for the Gstreamer bindings, which allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via unspecified vectors, which trigger a heap-based buffer overflow.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-8154">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2009-1438 – Integer overflow in the CSoundFile::ReadMed function (src/load_med.cpp) in libmo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-1438</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-1438</guid>
    <pubDate>Mon, 27 Apr 2009 18:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2009-1438</strong></p>
  <p>Integer overflow in the CSoundFile::ReadMed function (src/load_med.cpp) in libmodplug before 0.8.6, as used in gstreamer-plugins, TTPlayer, and other products, allows context-dependent attackers to execute arbitrary code via a MED file with a crafted (1) song comment or (2) song name, which triggers a heap-based buffer overflow, as exploited in the wild in August 2008.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-189</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-1438">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2009-0586 – Integer overflow in the gst_vorbis_tag_add_coverart function (gst-libs/gst/tag/g...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-0586</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-0586</guid>
    <pubDate>Sat, 14 Mar 2009 18:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2009-0586</strong></p>
  <p>Integer overflow in the gst_vorbis_tag_add_coverart function (gst-libs/gst/tag/gstvorbistag.c) in vorbistag in gst-plugins-base (aka gstreamer-plugins-base) before 0.10.23 in GStreamer allows context-dependent attackers to execute arbitrary code via a crafted COVERART tag that is converted from a base64 representation, which triggers a heap-based buffer overflow.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-0586">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2009-0398 – Array index error in the gst_qtp_trak_handler function in gst/qtdemux/qtdemux.c ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-0398</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-0398</guid>
    <pubDate>Tue, 03 Feb 2009 11:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2009-0398</strong></p>
  <p>Array index error in the gst_qtp_trak_handler function in gst/qtdemux/qtdemux.c in GStreamer Plug-ins (aka gstreamer-plugins) 0.6.0 allows remote attackers to have an unknown impact via a crafted QuickTime media file.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-0398">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2009-0397 – Heap-based buffer overflow in the qtdemux_parse_samples function in gst/qtdemux/...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-0397</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-0397</guid>
    <pubDate>Tue, 03 Feb 2009 11:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2009-0397</strong></p>
  <p>Heap-based buffer overflow in the qtdemux_parse_samples function in gst/qtdemux/qtdemux.c in GStreamer Good Plug-ins (aka gst-plugins-good) 0.10.9 through 0.10.11, and GStreamer Plug-ins (aka gstreamer-plugins) 0.8.5, might allow remote attackers to execute arbitrary code via crafted Time-to-sample (aka stts) atom data in a malformed QuickTime media .mov file.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-0397">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2009-0387 – Array index error in the qtdemux_parse_samples function in gst/qtdemux/qtdemux.c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-0387</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-0387</guid>
    <pubDate>Mon, 02 Feb 2009 19:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2009-0387</strong></p>
  <p>Array index error in the qtdemux_parse_samples function in gst/qtdemux/qtdemux.c in GStreamer Good Plug-ins (aka gst-plugins-good) 0.10.9 through 0.10.11 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted Sync Sample (aka stss) atom data in a malformed QuickTime media .mov file, related to "mark keyframes."</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-0387">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2009-0386 – Heap-based buffer overflow in the qtdemux_parse_samples function in gst/qtdemux/...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-0386</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-0386</guid>
    <pubDate>Mon, 02 Feb 2009 19:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2009-0386</strong></p>
  <p>Heap-based buffer overflow in the qtdemux_parse_samples function in gst/qtdemux/qtdemux.c in GStreamer Good Plug-ins (aka gst-plugins-good) 0.10.9 through 0.10.11 might allow remote attackers to execute arbitrary code via crafted Composition Time To Sample (ctts) atom data in a malformed QuickTime media .mov file.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-0386">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2005-4048 – Heap-based buffer overflow in the avcodec_default_get_buffer function (utils.c) ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2005-4048</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2005-4048</guid>
    <pubDate>Wed, 07 Dec 2005 11:03:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2005-4048</strong></p>
  <p>Heap-based buffer overflow in the avcodec_default_get_buffer function (utils.c) in FFmpeg libavcodec 0.4.9-pre1 and earlier, as used in products such as (1) mplayer, (2) xine-lib, (3) Xmovie, and (4) GStreamer, allows remote attackers to execute arbitrary commands via small PNG images with palettes.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2005-4048">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
