<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – GStreamer</title>
  <link>https://cvedaily.com/pages/tags/gstreamer.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/gstreamer.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – GStreamer</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:45 +0000</lastBuildDate>
  <item>
    <title>[Medium] CVE-2026-46470 – An issue was discovered in GStreamer gst-plugins-good before 1.28.2. When parsin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46470</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46470</guid>
    <pubDate>Thu, 14 May 2026 18:16:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-46470</strong></p>
  <p>An issue was discovered in GStreamer gst-plugins-good before 1.28.2. When parsing MP4 audio tracks, the isomp4 plugin's qtdemux_audio_caps function does not sufficiently validate atom data before performing division operations, leading to denial of service due to integer division by zero.</p>
  <p><strong>CVSS:</strong> 4.0 · <strong>CWE:</strong> CWE-369</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46470">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-46469 – An issue was discovered in GStreamer gst-plugins-good before 1.28.2. When parsin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46469</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46469</guid>
    <pubDate>Thu, 14 May 2026 18:16:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-46469</strong></p>
  <p>An issue was discovered in GStreamer gst-plugins-good before 1.28.2. When parsing MP4 audio tracks, the isomp4 plugin's qtdemux_parse_trak function does not sufficiently validate atom data before performing division operations, leading to denial of service due to integer division by zero.</p>
  <p><strong>CVSS:</strong> 4.0 · <strong>CWE:</strong> CWE-369</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46469">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-3086 – GStreamer H.266 Codec Parser Out-Of-Bounds Write Remote Code Execution Vulnerabi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3086</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3086</guid>
    <pubDate>Mon, 16 Mar 2026 14:19:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-3086</strong></p>
  <p>GStreamer H.266 Codec Parser Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation.  The specific flaw exists within the processing of APS units. The issue…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3086">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-3085 – GStreamer rtpqdm2depay Heap-based Buffer Overflow Remote Code Execution Vulnerab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3085</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3085</guid>
    <pubDate>Mon, 16 Mar 2026 14:19:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-3085</strong></p>
  <p>GStreamer rtpqdm2depay Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation.  The specific flaw exists within the processing of X-QDM RTP payloads.…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3085">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-3084 – GStreamer H.266 Codec Parser Integer Underflow Remote Code Execution Vulnerabili...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3084</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3084</guid>
    <pubDate>Mon, 16 Mar 2026 14:19:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-3084</strong></p>
  <p>GStreamer H.266 Codec Parser Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation.  The specific flaw exists within the parsing of picture partitions. The i…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-191</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3084">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-3083 – GStreamer rtpqdm2depay Out-Of-Bounds Write Remote Code Execution Vulnerability. ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3083</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3083</guid>
    <pubDate>Mon, 16 Mar 2026 14:19:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-3083</strong></p>
  <p>GStreamer rtpqdm2depay Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation.  The specific flaw exists within the processing of X-QDM RTP payload elements…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-129</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3083">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-3082 – GStreamer JPEG Parser Heap-based Buffer Overflow Remote Code Execution Vulnerabi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3082</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3082</guid>
    <pubDate>Mon, 16 Mar 2026 14:19:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-3082</strong></p>
  <p>GStreamer JPEG Parser Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation.  The specific flaw exists within the processing of Huffman tables. The…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3082">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-3081 – GStreamer H.266 Codec Parser Stack-based Buffer Overflow Remote Code Execution V...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3081</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3081</guid>
    <pubDate>Mon, 16 Mar 2026 14:19:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-3081</strong></p>
  <p>GStreamer H.266 Codec Parser Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation.  The specific flaw exists within the parsing of decoding units.…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3081">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-2923 – GStreamer DVB Subtitles Out-Of-Bounds Write Remote Code Execution Vulnerability...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2923</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2923</guid>
    <pubDate>Mon, 16 Mar 2026 14:19:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-2923</strong></p>
  <p>GStreamer DVB Subtitles Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation.  The specific flaw exists within the handling of coordinates. The issue resu…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2923">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-2922 – GStreamer RealMedia Demuxer Out-Of-Bounds Write Remote Code Execution Vulnerabil...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2922</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2922</guid>
    <pubDate>Mon, 16 Mar 2026 14:19:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-2922</strong></p>
  <p>GStreamer RealMedia Demuxer Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation.  The specific flaw exists within the processing of video packets. The is…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2922">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-2921 – GStreamer RIFF Palette Integer Overflow Remote Code Execution Vulnerability. Thi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2921</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2921</guid>
    <pubDate>Mon, 16 Mar 2026 14:19:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-2921</strong></p>
  <p>GStreamer RIFF Palette Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation.  The specific flaw exists within the handling of palette data in AVI files. The…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2921">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-2920 – GStreamer ASF Demuxer Heap-based Buffer Overflow Remote Code Execution Vulnerabi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2920</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2920</guid>
    <pubDate>Mon, 16 Mar 2026 14:19:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-2920</strong></p>
  <p>GStreamer ASF Demuxer Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation.  The specific flaw exists within the processing of stream headers withi…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2920">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Unknown] CVE-2025-68175 – In the Linux kernel, the following vulnerability has been resolved:

media: nxp:...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-68175</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-68175</guid>
    <pubDate>Tue, 16 Dec 2025 14:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk unknown">Unknown</span> CVE-2025-68175</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  media: nxp: imx8-isi: Fix streaming cleanup on release  The current implementation unconditionally calls mxc_isi_video_cleanup_streaming() in mxc_isi_video_release(). This can lead to situations where any release call (like from a simple "v4l2-ctl -l") may release a currently streaming queue when called on such a device.  This i…</p>
  <p><strong>CVSS:</strong> N/A · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68175">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-47808 – In GStreamer through 1.26.1, the subparse plugin's tmplayer_parse_line function ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-47808</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-47808</guid>
    <pubDate>Thu, 07 Aug 2025 20:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-47808</strong></p>
  <p>In GStreamer through 1.26.1, the subparse plugin's tmplayer_parse_line function may dereference a NULL pointer while parsing a subtitle file, leading to a crash.</p>
  <p><strong>CVSS:</strong> 5.6 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47808">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-47807 – In GStreamer through 1.26.1, the subparse plugin's subrip_unescape_formatting fu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-47807</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-47807</guid>
    <pubDate>Thu, 07 Aug 2025 20:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-47807</strong></p>
  <p>In GStreamer through 1.26.1, the subparse plugin's subrip_unescape_formatting function may dereference a NULL pointer while parsing a subtitle file, leading to a crash.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47807">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-47806 – In GStreamer through 1.26.1, the subparse plugin's parse_subrip_time function ma...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-47806</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-47806</guid>
    <pubDate>Thu, 07 Aug 2025 20:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-47806</strong></p>
  <p>In GStreamer through 1.26.1, the subparse plugin's parse_subrip_time function may write data past the bounds of a stack buffer, leading to a crash.</p>
  <p><strong>CVSS:</strong> 5.6 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47806">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-47219 – In GStreamer through 1.26.1, the isomp4 plugin's qtdemux_parse_trak function may...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-47219</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-47219</guid>
    <pubDate>Thu, 07 Aug 2025 20:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-47219</strong></p>
  <p>In GStreamer through 1.26.1, the isomp4 plugin's qtdemux_parse_trak function may read past the end of a heap buffer while parsing an MP4 file, possibly leading to information disclosure.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47219">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-47183 – In GStreamer through 1.26.1, the isomp4 plugin's qtdemux_parse_tree function may...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-47183</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-47183</guid>
    <pubDate>Thu, 07 Aug 2025 20:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-47183</strong></p>
  <p>In GStreamer through 1.26.1, the isomp4 plugin's qtdemux_parse_tree function may read past the end of a heap buffer while parsing an MP4 file, leading to information disclosure.</p>
  <p><strong>CVSS:</strong> 6.6 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47183">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-6663 – GStreamer H266 Codec Parsing Stack-based Buffer Overflow Remote Code Execution V...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-6663</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-6663</guid>
    <pubDate>Mon, 07 Jul 2025 15:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-6663</strong></p>
  <p>GStreamer H266 Codec Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation.  The specific flaw exists within the parsing of H266 sei messag…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-6663">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-3887 – GStreamer H265 Codec Parsing Stack-based Buffer Overflow Remote Code Execution V...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-3887</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-3887</guid>
    <pubDate>Thu, 22 May 2025 01:15:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-3887</strong></p>
  <p>GStreamer H265 Codec Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation.  The specific flaw exists within the parsing of H265 slice head…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-3887">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-2759 – GStreamer Incorrect Permission Assignment Local Privilege Escalation Vulnerabili...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-2759</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-2759</guid>
    <pubDate>Thu, 22 May 2025 01:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-2759</strong></p>
  <p>GStreamer Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of GStreamer. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.  The specific flaw exists within the product installer. The issue results fr…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-2759">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-47835 – GStreamer is a library for constructing graphs of media-handling components. A n...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47835</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47835</guid>
    <pubDate>Thu, 12 Dec 2024 02:03:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-47835</strong></p>
  <p>GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference vulnerability has been detected in the parse_lrc function within gstsubparse.c. The parse_lrc function calls strchr() to find the character ']' in the string line. The pointer returned by this call is then passed to g_strdup(). However, if the string line does not contain the character ']', str…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47835">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-47834 – GStreamer is a library for constructing graphs of media-handling components. An ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47834</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47834</guid>
    <pubDate>Thu, 12 Dec 2024 02:03:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-47834</strong></p>
  <p>GStreamer is a library for constructing graphs of media-handling components. An Use-After-Free read vulnerability has been discovered affecting the processing of CodecPrivate elements in Matroska streams. In the GST_MATROSKA_ID_CODECPRIVATE case within the gst_matroska_demux_parse_stream function, a data chunk is allocated using gst_ebml_read_binary. Later, the allocated memory is freed in the gs…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47834">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-47778 – GStreamer is a library for constructing graphs of media-handling components. An ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47778</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47778</guid>
    <pubDate>Thu, 12 Dec 2024 02:03:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-47778</strong></p>
  <p>GStreamer is a library for constructing graphs of media-handling components. An OOB-read vulnerability has been discovered in gst_wavparse_adtl_chunk within gstwavparse.c. This vulnerability arises due to insufficient validation of the size parameter, which can exceed the bounds of the data buffer. As a result, an OOB read occurs in the following while loop. This vulnerability can result in readi…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47778">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-47777 – GStreamer is a library for constructing graphs of media-handling components. An ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47777</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47777</guid>
    <pubDate>Thu, 12 Dec 2024 02:03:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-47777</strong></p>
  <p>GStreamer is a library for constructing graphs of media-handling components. An OOB-read vulnerability has been identified in the gst_wavparse_smpl_chunk function within gstwavparse.c. This function attempts to read 4 bytes from the data + 12 offset without checking if the size of the data buffer is sufficient. If the buffer is too small, the function reads beyond its bounds. This vulnerability m…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47777">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-47776 – GStreamer is a library for constructing graphs of media-handling components. An ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47776</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47776</guid>
    <pubDate>Thu, 12 Dec 2024 02:03:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-47776</strong></p>
  <p>GStreamer is a library for constructing graphs of media-handling components. An OOB-read has been discovered in gst_wavparse_cue_chunk within gstwavparse.c. The vulnerability happens due to a discrepancy between the size of the data buffer and the size value provided to the function. This mismatch causes the comparison  if (size < 4 + ncues * 24) to fail in some cases, allowing the subsequent loo…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47776">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-47775 – GStreamer is a library for constructing graphs of media-handling components. An ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47775</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47775</guid>
    <pubDate>Thu, 12 Dec 2024 02:03:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-47775</strong></p>
  <p>GStreamer is a library for constructing graphs of media-handling components. An OOB-read vulnerability has been found in the parse_ds64 function within gstwavparse.c. The parse_ds64 function does not check that the buffer buf contains sufficient data before attempting to read from it, doing multiple GST_READ_UINT32_LE operations without performing boundary checks. This can lead to an OOB-read whe…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47775">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-47774 – GStreamer is a library for constructing graphs of media-handling components. An ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47774</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47774</guid>
    <pubDate>Thu, 12 Dec 2024 02:03:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-47774</strong></p>
  <p>GStreamer is a library for constructing graphs of media-handling components. An OOB-read vulnerability has been identified in the gst_avi_subtitle_parse_gab2_chunk function within gstavisubtitle.c. The function reads the name_length value directly from the input file without checking it properly. Then, the a condition, does not properly handle cases where name_length is greater than 0xFFFFFFFF -…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47774">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-47615 – GStreamer is a library for constructing graphs of media-handling components. An ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47615</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47615</guid>
    <pubDate>Thu, 12 Dec 2024 02:03:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-47615</strong></p>
  <p>GStreamer is a library for constructing graphs of media-handling components. An OOB-Write has been detected in the function gst_parse_vorbis_setup_packet within vorbis_parse.c. The integer size is read from the input file without proper validation. As a result, size can exceed the fixed size of the pad->vorbis_mode_sizes array (which size is 256). When this happens, the for loop overwrites the en…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47615">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-47613 – GStreamer is a library for constructing graphs of media-handling components. A n...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47613</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47613</guid>
    <pubDate>Thu, 12 Dec 2024 02:03:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-47613</strong></p>
  <p>GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference vulnerability has been identified in `gst_gdk_pixbuf_dec_flush` within `gstgdkpixbufdec.c`. This function invokes `memcpy`, using `out_pix` as the destination address. `out_pix` is expected to point to the frame 0 from the frame structure, which is read from the input file. However, in certain…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47613">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-47607 – GStreamer is a library for constructing graphs of media-handling components.  st...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47607</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47607</guid>
    <pubDate>Thu, 12 Dec 2024 02:03:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-47607</strong></p>
  <p>GStreamer is a library for constructing graphs of media-handling components.  stack-buffer overflow has been detected in the gst_opus_dec_parse_header function within `gstopusdec.c'. The pos array is a stack-allocated buffer of size 64. If n_channels exceeds 64, the for loop will write beyond the boundaries of the pos array. The value written will always be GST_AUDIO_CHANNEL_POSITION_NONE. This b…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47607">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-47606 – GStreamer is a library for constructing graphs of media-handling components. An ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47606</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47606</guid>
    <pubDate>Thu, 12 Dec 2024 02:03:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-47606</strong></p>
  <p>GStreamer is a library for constructing graphs of media-handling components. An integer underflow has been detected in the function qtdemux_parse_theora_extension within qtdemux.c. The vulnerability occurs due to an underflow of the gint size variable, which causes size to hold a large unintended value when cast to an unsigned integer. This 32-bit negative value is then cast to a 64-bit unsigned…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47606">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-47603 – GStreamer is a library for constructing graphs of media-handling components. A n...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47603</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47603</guid>
    <pubDate>Thu, 12 Dec 2024 02:03:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-47603</strong></p>
  <p>GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference vulnerability has been discovered in the gst_matroska_demux_update_tracks function within matroska-demux.c. The vulnerability occurs when the gst_caps_is_equal function is called with invalid caps values. If this happen, then in the function gst_buffer_get_size the call to GST_BUFFER_MEM_PTR ca…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47603">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-47602 – GStreamer is a library for constructing graphs of media-handling components. A n...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47602</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47602</guid>
    <pubDate>Thu, 12 Dec 2024 02:03:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-47602</strong></p>
  <p>GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference vulnerability has been discovered in the gst_matroska_demux_add_wvpk_header function within matroska-demux.c. This function does not properly check the validity of the stream->codec_priv pointer in the following code. If stream->codec_priv is NULL, the call to GST_READ_UINT16_LE will attempt to…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47602">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-47601 – GStreamer is a library for constructing graphs of media-handling components. A n...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47601</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47601</guid>
    <pubDate>Thu, 12 Dec 2024 02:03:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-47601</strong></p>
  <p>GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference vulnerability has been discovered in the gst_matroska_demux_parse_blockgroup_or_simpleblock function within matroska-demux.c. This function does not properly check the validity of the GstBuffer *sub pointer before performing dereferences. As a result, null pointer dereferences may occur. This v…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47601">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-47600 – GStreamer is a library for constructing graphs of media-handling components. An ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47600</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47600</guid>
    <pubDate>Thu, 12 Dec 2024 02:03:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-47600</strong></p>
  <p>GStreamer is a library for constructing graphs of media-handling components. An OOB-read vulnerability has been detected in the format_channel_mask function in gst-discoverer.c. The vulnerability affects the local array position, which is defined with a fixed size of 64 elements. However, the function gst_discoverer_audio_info_get_channels may return a guint channels value greater than 64. This c…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47600">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-47599 – GStreamer is a library for constructing graphs of media-handling components. A n...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47599</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47599</guid>
    <pubDate>Thu, 12 Dec 2024 02:03:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-47599</strong></p>
  <p>GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference vulnerability has been discovered in the gst_jpeg_dec_negotiate function in gstjpegdec.c. This function does not check for a NULL return value from gst_video_decoder_set_output_state. When this happens, dereferences of the outstate pointer will lead to a null pointer dereference. This vulnerabi…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47599">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-47598 – GStreamer is a library for constructing graphs of media-handling components. An ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47598</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47598</guid>
    <pubDate>Thu, 12 Dec 2024 02:03:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-47598</strong></p>
  <p>GStreamer is a library for constructing graphs of media-handling components. An OOB-read vulnerability has been discovered in the qtdemux_merge_sample_table function within qtdemux.c. The problem is that the size of the stts buffer isn’t properly checked before reading stts_duration, allowing the program to read 4 bytes beyond the boundaries of stts->data. This vulnerability reads up to 4 bytes p…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47598">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-47597 – GStreamer is a library for constructing graphs of media-handling components. An ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47597</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47597</guid>
    <pubDate>Thu, 12 Dec 2024 02:03:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-47597</strong></p>
  <p>GStreamer is a library for constructing graphs of media-handling components. An OOB-read has been detected in the function qtdemux_parse_samples within qtdemux.c. This issue arises when the function qtdemux_parse_samples reads data beyond the boundaries of the stream->stco buffer. The following code snippet shows the call to qt_atom_parser_get_offset_unchecked, which leads to the OOB-read when pa…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47597">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-47596 – GStreamer is a library for constructing graphs of media-handling components. An ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47596</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47596</guid>
    <pubDate>Thu, 12 Dec 2024 02:03:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-47596</strong></p>
  <p>GStreamer is a library for constructing graphs of media-handling components. An OOB-read has been discovered in the qtdemux_parse_svq3_stsd_data function within qtdemux.c. In the FOURCC_SMI_ case, seqh_size is read from the input file without proper validation. If seqh_size is greater than the remaining size of the data buffer, it can lead to an OOB-read in the following call to gst_buffer_fill,…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47596">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-47546 – GStreamer is a library for constructing graphs of media-handling components. An ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47546</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47546</guid>
    <pubDate>Thu, 12 Dec 2024 02:03:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-47546</strong></p>
  <p>GStreamer is a library for constructing graphs of media-handling components. An integer underflow has been detected in extract_cc_from_data function within qtdemux.c. In the FOURCC_c708 case, the subtraction atom_length - 8 may result in an underflow if atom_length is less than 8. When that subtraction underflows, *cclen ends up being a large number, and then cclen is passed to g_memdup2 leading…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-191</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47546">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-47545 – GStreamer is a library for constructing graphs of media-handling components. An ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47545</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47545</guid>
    <pubDate>Thu, 12 Dec 2024 02:03:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-47545</strong></p>
  <p>GStreamer is a library for constructing graphs of media-handling components. An integer underflow has been detected in qtdemux_parse_trak function within qtdemux.c. During the strf parsing case, the subtraction size -= 40 can lead to a negative integer overflow if it is less than 40. If this happens, the subsequent call to gst_buffer_fill will invoke memcpy with a large tocopy size, resulting in…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-191</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47545">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-47544 – GStreamer is a library for constructing graphs of media-handling components. The...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47544</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47544</guid>
    <pubDate>Thu, 12 Dec 2024 02:03:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-47544</strong></p>
  <p>GStreamer is a library for constructing graphs of media-handling components. The function qtdemux_parse_sbgp in qtdemux.c is affected by a null dereference vulnerability. This vulnerability is fixed in 1.24.10.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47544">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-47543 – GStreamer is a library for constructing graphs of media-handling components. An ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47543</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47543</guid>
    <pubDate>Thu, 12 Dec 2024 02:03:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-47543</strong></p>
  <p>GStreamer is a library for constructing graphs of media-handling components. An OOB-read vulnerability has been discovered in qtdemux_parse_container function within qtdemux.c. In the parent function qtdemux_parse_node, the value of length is not well checked. So, if length is big enough, it causes the pointer end to point beyond the boundaries of buffer. Subsequently, in the qtdemux_parse_contai…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47543">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-47542 – GStreamer is a library for constructing graphs of media-handling components. A n...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47542</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47542</guid>
    <pubDate>Thu, 12 Dec 2024 02:03:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-47542</strong></p>
  <p>GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference has been discovered in the id3v2_read_synch_uint function, located in id3v2.c. If id3v2_read_synch_uint is called with a null work->hdr.frame_data, the pointer guint8 *data is accessed without validation, resulting in a null pointer dereference. This vulnerability can result in a Denial of Serv…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47542">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-47541 – GStreamer is a library for constructing graphs of media-handling components. An ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47541</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47541</guid>
    <pubDate>Thu, 12 Dec 2024 02:03:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-47541</strong></p>
  <p>GStreamer is a library for constructing graphs of media-handling components. An OOB-write vulnerability has been identified in the gst_ssa_parse_remove_override_codes function of the gstssaparse.c file. This function is responsible for parsing and removing SSA (SubStation Alpha) style override codes, which are enclosed in curly brackets ({}). The issue arises when a closing curly bracket "}" appe…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47541">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-47540 – GStreamer is a library for constructing graphs of media-handling components. An ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47540</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47540</guid>
    <pubDate>Thu, 12 Dec 2024 02:03:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-47540</strong></p>
  <p>GStreamer is a library for constructing graphs of media-handling components. An uninitialized stack variable vulnerability has been identified in the gst_matroska_demux_add_wvpk_header function within matroska-demux.c. When size < 4, the program calls gst_buffer_unmap with an uninitialized map variable. Then, in the gst_memory_unmap function, the program will attempt to unmap the buffer using the…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-457</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47540">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-47539 – GStreamer is a library for constructing graphs of media-handling components. An ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47539</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47539</guid>
    <pubDate>Thu, 12 Dec 2024 02:03:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-47539</strong></p>
  <p>GStreamer is a library for constructing graphs of media-handling components. An out-of-bounds write vulnerability was identified in the convert_to_s334_1a function in isomp4/qtdemux.c. The vulnerability arises due to a discrepancy between the size of memory allocated to the storage array and the loop condition i * 2 < ccpair_size. Specifically, when ccpair_size is even, the allocated size in stor…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47539">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-47538 – GStreamer is a library for constructing graphs of media-handling components. A s...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47538</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47538</guid>
    <pubDate>Thu, 12 Dec 2024 02:03:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-47538</strong></p>
  <p>GStreamer is a library for constructing graphs of media-handling components. A stack-buffer overflow has been detected in the `vorbis_handle_identification_packet` function within `gstvorbisdec.c`. The position array is a stack-allocated buffer of size 64. If vd->vi.channels exceeds 64, the for loop will write beyond the boundaries of the position array. The value written will always be `GST_AUDI…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47538">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-47537 – GStreamer is a library for constructing graphs of media-handling components. The...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47537</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47537</guid>
    <pubDate>Thu, 12 Dec 2024 02:03:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-47537</strong></p>
  <p>GStreamer is a library for constructing graphs of media-handling components. The program attempts to reallocate the memory pointed to by stream->samples to accommodate stream->n_samples + samples_count elements of type QtDemuxSample. The problem is that samples_count is read from the input file. And if this value is big enough, this can lead to an integer overflow during the addition. As a conseq…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47537">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-44331 – Incorrect Access Control in GStreamer RTSP server 1.25.0 in gst-rtsp-server/rtsp...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-44331</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-44331</guid>
    <pubDate>Tue, 22 Oct 2024 22:15:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-44331</strong></p>
  <p>Incorrect Access Control in GStreamer RTSP server 1.25.0 in gst-rtsp-server/rtsp-media.c allows remote attackers to cause a denial of service via a series of specially crafted hexstream requests.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-44331">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-0444 – GStreamer AV1 Video Parsing Stack-based Buffer Overflow Remote Code Execution Vu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-0444</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-0444</guid>
    <pubDate>Fri, 07 Jun 2024 23:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-0444</strong></p>
  <p>GStreamer AV1 Video Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation.  The specific flaw exists within the parsing of tile list data w…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-0444">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-4453 – GStreamer EXIF Metadata Parsing Integer Overflow Remote Code Execution Vulnerabi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-4453</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-4453</guid>
    <pubDate>Wed, 22 May 2024 20:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-4453</strong></p>
  <p>GStreamer EXIF Metadata Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation.  The specific flaw exists within the parsing of EXIF metadata. The issu…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-4453">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-50186 – GStreamer AV1 Video Parsing Stack-based Buffer Overflow Remote Code Execution Vu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-50186</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-50186</guid>
    <pubDate>Fri, 03 May 2024 03:16:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-50186</strong></p>
  <p>GStreamer AV1 Video Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation.  The specific flaw exists within the parsing of metadata within…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-50186">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-44446 – GStreamer MXF File Parsing Use-After-Free Remote Code Execution Vulnerability. T...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-44446</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-44446</guid>
    <pubDate>Fri, 03 May 2024 03:16:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-44446</strong></p>
  <p>GStreamer MXF File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation.  The specific flaw exists within the parsing of MXF video files. The issue res…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-44446">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-44429 – GStreamer AV1 Codec Parsing Heap-based Buffer Overflow Remote Code Execution Vul...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-44429</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-44429</guid>
    <pubDate>Fri, 03 May 2024 03:15:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-44429</strong></p>
  <p>GStreamer AV1 Codec Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation.  The specific flaw exists within the parsing of AV1 encoded video…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-44429">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-40476 – GStreamer H265 Parsing Stack-based Buffer Overflow Remote Code Execution Vulnera...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-40476</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-40476</guid>
    <pubDate>Fri, 03 May 2024 03:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-40476</strong></p>
  <p>GStreamer H265 Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation.  The specific flaw exists within the parsing of H265 encoded video fi…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-40476">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-40475 – GStreamer MXF File Parsing Integer Overflow Remote Code Execution Vulnerability...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-40475</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-40475</guid>
    <pubDate>Fri, 03 May 2024 03:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-40475</strong></p>
  <p>GStreamer MXF File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation.  The specific flaw exists within the parsing of MXF video files. The issue r…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-40475">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-40474 – GStreamer MXF File Parsing Integer Overflow Remote Code Execution Vulnerability...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-40474</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-40474</guid>
    <pubDate>Fri, 03 May 2024 03:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-40474</strong></p>
  <p>GStreamer MXF File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation.  The specific flaw exists within the parsing of MXF video files. The issue r…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-40474">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-38104 – GStreamer RealMedia File Parsing Integer Overflow Remote Code Execution Vulnerab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-38104</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-38104</guid>
    <pubDate>Fri, 03 May 2024 02:15:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-38104</strong></p>
  <p>GStreamer RealMedia File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation.  The specific flaw exists within the parsing of MDPR chunks. The issue…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-38104">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-38103 – GStreamer RealMedia File Parsing Integer Overflow Remote Code Execution Vulnerab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-38103</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-38103</guid>
    <pubDate>Fri, 03 May 2024 02:15:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-38103</strong></p>
  <p>GStreamer RealMedia File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation.  The specific flaw exists within the parsing of MDPR chunks. The issue…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-38103">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-37329 – GStreamer SRT File Parsing Heap-based Buffer Overflow Remote Code Execution Vuln...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-37329</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-37329</guid>
    <pubDate>Fri, 03 May 2024 02:15:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-37329</strong></p>
  <p>GStreamer SRT File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation.  The specific flaw exists within the parsing of SRT subtitle files…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-37329">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-37328 – GStreamer PGS File Parsing Heap-based Buffer Overflow Remote Code Execution Vuln...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-37328</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-37328</guid>
    <pubDate>Fri, 03 May 2024 02:15:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-37328</strong></p>
  <p>GStreamer PGS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation.  The specific flaw exists within the parsing of PGS subtitle files…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-37328">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-37327 – GStreamer FLAC File Parsing Integer Overflow Remote Code Execution Vulnerability...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-37327</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-37327</guid>
    <pubDate>Fri, 03 May 2024 02:15:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-37327</strong></p>
  <p>GStreamer FLAC File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation.  The specific flaw exists within the parsing of FLAC audio files. The issue…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-37327">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-6185 – Improper Input Validation vulnerability in GStreamer integration of The Document...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-6185</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-6185</guid>
    <pubDate>Mon, 11 Dec 2023 12:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-6185</strong></p>
  <p>Improper Input Validation vulnerability in GStreamer integration of The Document Foundation LibreOffice allows an attacker to execute arbitrary GStreamer plugins.  In affected versions the filename of the embedded video is not sufficiently escaped when passed to GStreamer enabling an attacker to run arbitrary gstreamer plugins depending on what plugins are installed on the target system.</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-6185">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-3522 – GStreamer before 1.18.4 may perform an out-of-bounds read when handling certain ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-3522</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-3522</guid>
    <pubDate>Wed, 02 Jun 2021 15:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-3522</strong></p>
  <p>GStreamer before 1.18.4 may perform an out-of-bounds read when handling certain ID3v2 tags.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-3522">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-3498 – GStreamer before 1.18.4 might cause heap corruption when parsing certain malform...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-3498</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-3498</guid>
    <pubDate>Mon, 19 Apr 2021 21:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-3498</strong></p>
  <p>GStreamer before 1.18.4 might cause heap corruption when parsing certain malformed Matroska files.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-3498">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-3497 – GStreamer before 1.18.4 might access already-freed memory in error code paths wh...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-3497</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-3497</guid>
    <pubDate>Mon, 19 Apr 2021 21:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-3497</strong></p>
  <p>GStreamer before 1.18.4 might access already-freed memory in error code paths when demuxing certain malformed Matroska files.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-3497">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-3185 – A flaw was found in the gstreamer h264 component of gst-plugins-bad before v1.18...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-3185</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-3185</guid>
    <pubDate>Tue, 26 Jan 2021 18:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-3185</strong></p>
  <p>A flaw was found in the gstreamer h264 component of gst-plugins-bad before v1.18.1 where when parsing a h264 header, an attacker could cause the stack to be smashed, memory corruption and possibly code execution.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-3185">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-6095 – An exploitable denial of service vulnerability exists in the GstRTSPAuth functio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-6095</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-6095</guid>
    <pubDate>Fri, 27 Mar 2020 20:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-6095</strong></p>
  <p>An exploitable denial of service vulnerability exists in the GstRTSPAuth functionality of GStreamer/gst-rtsp-server 1.14.5. A specially crafted RTSP setup request can cause a null pointer deference resulting in denial-of-service. An attacker can send a malicious packet to trigger this vulnerability.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-690</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-6095">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2013-7324 – Webkit-GTK 2.x (any version with HTML5 audio/video support based on GStreamer) a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-7324</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-7324</guid>
    <pubDate>Mon, 17 Feb 2020 19:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2013-7324</strong></p>
  <p>Webkit-GTK 2.x (any version with HTML5 audio/video support based on GStreamer) allows remote attackers to trigger unexpectedly high sound volume via malicious javascript. NOTE: this WebKit-GTK behavior complies with existing W3C standards and existing practices for GNOME desktop integration.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-7324">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-9928 – GStreamer before 1.16.0 has a heap-based buffer overflow in the RTSP connection ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-9928</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-9928</guid>
    <pubDate>Wed, 24 Apr 2019 15:29:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-9928</strong></p>
  <p>GStreamer before 1.16.0 has a heap-based buffer overflow in the RTSP connection parser via a crafted response from a server, potentially allowing remote code execution.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-9928">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-5848 – The gst_ps_demux_parse_psm function in gst/mpegdemux/gstmpegdemux.c in gst-plugi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-5848</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-5848</guid>
    <pubDate>Thu, 09 Feb 2017 15:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-5848</strong></p>
  <p>The gst_ps_demux_parse_psm function in gst/mpegdemux/gstmpegdemux.c in gst-plugins-bad in GStreamer allows remote attackers to cause a denial of service (invalid memory read and crash) via vectors involving PSM parsing.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-5848">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-5847 – The gst_asf_demux_process_ext_content_desc function in gst/asfdemux/gstasfdemux...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-5847</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-5847</guid>
    <pubDate>Thu, 09 Feb 2017 15:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-5847</strong></p>
  <p>The gst_asf_demux_process_ext_content_desc function in gst/asfdemux/gstasfdemux.c in gst-plugins-ugly in GStreamer allows remote attackers to cause a denial of service (out-of-bounds heap read) via vectors involving extended content descriptors.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-5847">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2017-5846 – The gst_asf_demux_process_ext_stream_props function in gst/asfdemux/gstasfdemux...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-5846</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-5846</guid>
    <pubDate>Thu, 09 Feb 2017 15:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2017-5846</strong></p>
  <p>The gst_asf_demux_process_ext_stream_props function in gst/asfdemux/gstasfdemux.c in gst-plugins-ugly in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (invalid memory read and crash) via vectors related to the number of languages in a video file.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-5846">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-5845 – The gst_avi_demux_parse_ncdt function in gst/avi/gstavidemux.c in gst-plugins-go...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-5845</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-5845</guid>
    <pubDate>Thu, 09 Feb 2017 15:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-5845</strong></p>
  <p>The gst_avi_demux_parse_ncdt function in gst/avi/gstavidemux.c in gst-plugins-good in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (invalid memory read and crash) via a ncdt sub-tag that "goes behind" the surrounding tag.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-5845">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2017-5844 – The gst_riff_create_audio_caps function in gst-libs/gst/riff/riff-media.c in gst...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-5844</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-5844</guid>
    <pubDate>Thu, 09 Feb 2017 15:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2017-5844</strong></p>
  <p>The gst_riff_create_audio_caps function in gst-libs/gst/riff/riff-media.c in gst-plugins-base in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (floating point exception and crash) via a crafted ASF file.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-369</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-5844">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-5843 – Multiple use-after-free vulnerabilities in the (1) gst_mini_object_unref, (2) gs...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-5843</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-5843</guid>
    <pubDate>Thu, 09 Feb 2017 15:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-5843</strong></p>
  <p>Multiple use-after-free vulnerabilities in the (1) gst_mini_object_unref, (2) gst_tag_list_unref, and (3) gst_mxf_demux_update_essence_tracks functions in GStreamer before 1.10.3 allow remote attackers to cause a denial of service (crash) via vectors involving stream tags, as demonstrated by 02785736.mxf.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-5843">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2017-5842 – The html_context_handle_element function in gst/subparse/samiparse.c in gst-plug...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-5842</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-5842</guid>
    <pubDate>Thu, 09 Feb 2017 15:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2017-5842</strong></p>
  <p>The html_context_handle_element function in gst/subparse/samiparse.c in gst-plugins-base in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted SMI file, as demonstrated by OneNote_Manager.smi.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-5842">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-5841 – The gst_avi_demux_parse_ncdt function in gst/avi/gstavidemux.c in gst-plugins-go...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-5841</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-5841</guid>
    <pubDate>Thu, 09 Feb 2017 15:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-5841</strong></p>
  <p>The gst_avi_demux_parse_ncdt function in gst/avi/gstavidemux.c in gst-plugins-good in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (out-of-bounds heap read) via vectors involving ncdt tags.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-5841">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-5840 – The qtdemux_parse_samples function in gst/isomp4/qtdemux.c in gst-plugins-good i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-5840</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-5840</guid>
    <pubDate>Thu, 09 Feb 2017 15:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-5840</strong></p>
  <p>The qtdemux_parse_samples function in gst/isomp4/qtdemux.c in gst-plugins-good in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (out-of-bounds heap read) via vectors involving the current stts index.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-5840">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-5839 – The gst_riff_create_audio_caps function in gst-libs/gst/riff/riff-media.c in gst...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-5839</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-5839</guid>
    <pubDate>Thu, 09 Feb 2017 15:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-5839</strong></p>
  <p>The gst_riff_create_audio_caps function in gst-libs/gst/riff/riff-media.c in gst-plugins-base in GStreamer before 1.10.3 does not properly limit recursion, which allows remote attackers to cause a denial of service (stack overflow and crash) via vectors involving nested WAVEFORMATEX.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-674</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-5839">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-5838 – The gst_date_time_new_from_iso8601_string function in gst/gstdatetime.c in GStre...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-5838</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-5838</guid>
    <pubDate>Thu, 09 Feb 2017 15:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-5838</strong></p>
  <p>The gst_date_time_new_from_iso8601_string function in gst/gstdatetime.c in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a malformed datetime string.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-5838">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2017-5837 – The gst_riff_create_audio_caps function in gst-libs/gst/riff/riff-media.c in gst...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-5837</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-5837</guid>
    <pubDate>Thu, 09 Feb 2017 15:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2017-5837</strong></p>
  <p>The gst_riff_create_audio_caps function in gst-libs/gst/riff/riff-media.c in gst-plugins-base in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (floating point exception and crash) via a crafted video file.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-369</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-5837">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-10199 – The qtdemux_tag_add_str_full function in gst/isomp4/qtdemux.c in gst-plugins-goo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-10199</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-10199</guid>
    <pubDate>Thu, 09 Feb 2017 15:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-10199</strong></p>
  <p>The qtdemux_tag_add_str_full function in gst/isomp4/qtdemux.c in gst-plugins-good in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted tag value.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-10199">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-10198 – The gst_aac_parse_sink_setcaps function in gst/audioparsers/gstaacparse.c in gst...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-10198</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-10198</guid>
    <pubDate>Thu, 09 Feb 2017 15:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-10198</strong></p>
  <p>The gst_aac_parse_sink_setcaps function in gst/audioparsers/gstaacparse.c in gst-plugins-good in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (invalid memory read and crash) via a crafted audio file.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-10198">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2016-9636 – Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstfl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-9636</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-9636</guid>
    <pubDate>Fri, 27 Jan 2017 22:59:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2016-9636</strong></p>
  <p>Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstflxdec.c in the FLIC decoder in GStreamer before 1.10.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) by providing a 'write count' that goes beyond the initialized buffer.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-9636">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2016-9635 – Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstfl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-9635</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-9635</guid>
    <pubDate>Fri, 27 Jan 2017 22:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2016-9635</strong></p>
  <p>Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstflxdec.c in the FLIC decoder in GStreamer before 1.10.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) by providing a 'skip count' that goes beyond initialized buffer.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-9635">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2016-9634 – Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstfl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-9634</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-9634</guid>
    <pubDate>Fri, 27 Jan 2017 22:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2016-9634</strong></p>
  <p>Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstflxdec.c in the FLIC decoder in GStreamer before 1.10.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via the start_line parameter.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-9634">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-9447 – The ROM mappings in the NSF decoder in gstreamer 0.10.x allow remote attackers t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-9447</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-9447</guid>
    <pubDate>Mon, 23 Jan 2017 21:59:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-9447</strong></p>
  <p>The ROM mappings in the NSF decoder in gstreamer 0.10.x allow remote attackers to cause a denial of service (out-of-bounds read or write) and possibly execute arbitrary code via a crafted NSF music file.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-9447">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-9446 – The vmnc decoder in the gstreamer does not initialize the render canvas, which a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-9446</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-9446</guid>
    <pubDate>Mon, 23 Jan 2017 21:59:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-9446</strong></p>
  <p>The vmnc decoder in the gstreamer does not initialize the render canvas, which allows remote attackers to obtain sensitive information as demonstrated by thumbnailing a simple 1 frame vmnc movie that does not draw to the allocated render canvas.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-665</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-9446">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-9445 – Integer overflow in the vmnc decoder in the gstreamer allows remote attackers to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-9445</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-9445</guid>
    <pubDate>Mon, 23 Jan 2017 21:59:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-9445</strong></p>
  <p>Integer overflow in the vmnc decoder in the gstreamer allows remote attackers to cause a denial of service (crash) via large width and height values, which triggers a buffer overflow.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-9445">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-9813 – The _parse_pat function in the mpegts parser in GStreamer before 1.10.2 allows r...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-9813</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-9813</guid>
    <pubDate>Fri, 13 Jan 2017 16:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-9813</strong></p>
  <p>The _parse_pat function in the mpegts parser in GStreamer before 1.10.2 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted file.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-9813">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-9812 – The gst_mpegts_section_new function in the mpegts decoder in GStreamer before 1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-9812</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-9812</guid>
    <pubDate>Fri, 13 Jan 2017 16:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-9812</strong></p>
  <p>The gst_mpegts_section_new function in the mpegts decoder in GStreamer before 1.10.2 allows remote attackers to cause a denial of service (out-of-bounds read) via a too small section.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-9812">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-9811 – The windows_icon_typefind function in gst-plugins-base in GStreamer before 1.10...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-9811</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-9811</guid>
    <pubDate>Fri, 13 Jan 2017 16:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-9811</strong></p>
  <p>The windows_icon_typefind function in gst-plugins-base in GStreamer before 1.10.2, when G_SLICE is set to always-malloc, allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted ico file.</p>
  <p><strong>CVSS:</strong> 4.7 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-9811">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-9810 – The gst_decode_chain_free_internal function in the flxdex decoder in gst-plugins...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-9810</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-9810</guid>
    <pubDate>Fri, 13 Jan 2017 16:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-9810</strong></p>
  <p>The gst_decode_chain_free_internal function in the flxdex decoder in gst-plugins-good in GStreamer before 1.10.2 allows remote attackers to cause a denial of service (invalid memory read and crash) via an invalid file, which triggers an incorrect unref call.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-9810">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-9809 – Off-by-one error in the gst_h264_parse_set_caps function in GStreamer before 1.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-9809</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-9809</guid>
    <pubDate>Fri, 13 Jan 2017 16:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-9809</strong></p>
  <p>Off-by-one error in the gst_h264_parse_set_caps function in GStreamer before 1.10.2 allows remote attackers to have unspecified impact via a crafted file, which triggers an out-of-bounds read.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-9809">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-9808 – The FLIC decoder in GStreamer before 1.10.2 allows remote attackers to cause a d...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-9808</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-9808</guid>
    <pubDate>Fri, 13 Jan 2017 16:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-9808</strong></p>
  <p>The FLIC decoder in GStreamer before 1.10.2 allows remote attackers to cause a denial of service (out-of-bounds write and crash) via a crafted series of skip and count pairs.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-9808">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-9807 – The flx_decode_chunks function in gst/flx/gstflxdec.c in GStreamer before 1.10.2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-9807</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-9807</guid>
    <pubDate>Fri, 13 Jan 2017 16:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-9807</strong></p>
  <p>The flx_decode_chunks function in gst/flx/gstflxdec.c in GStreamer before 1.10.2 allows remote attackers to cause a denial of service (invalid memory read and crash) via a crafted FLIC file.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-9807">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2015-0797 – GStreamer before 1.4.5, as used in Mozilla Firefox before 38.0, Firefox ESR 31.x...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-0797</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-0797</guid>
    <pubDate>Thu, 14 May 2015 10:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2015-0797</strong></p>
  <p>GStreamer before 1.4.5, as used in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 on Linux, allows remote attackers to cause a denial of service (buffer over-read and application crash) or possibly execute arbitrary code via crafted H.264 video data in an m4v file.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-0797">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
