Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
138 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.1) | 0.63% | — | Gstreamer Gst-plugins-badAI | 15/6/2026 | 30/7/2026 | An out-of-bounds read vulnerability was found in the VA JPEG decoder in GStreamer's gst-plugins-bad. The JPEG parser reads a segment length value from the bitstream without validating it against available data. A remote attacker could trick a user into opening a specially crafted JPEG file, causing downstream parsing… | |
| Pendiente de análisis | Media (6.5) | 0.71% | — | Gstreamer Gst-plugins-badAI | 15/6/2026 | 30/7/2026 | A denial of service vulnerability was found in GStreamer's AV1 codec parser in gst-plugins-bad. The gst_av1_parser_parse_tile_list_obu() function passes a byte count to a bit-reader API that expects a bit count, causing parser desynchronization. A remote attacker could trick a user into opening a specially crafted AV1… | |
| Pendiente de análisis | Media (6.5) | 0.40% | — | Gstreamer Gst-plugins-badAI | 11/6/2026 | 17/6/2026 | A stack buffer overflow flaw was found in the GStreamer H.265 codec parser library (gst-plugins-bad). When parsing a buffering period SEI message, the parser uses an incorrect loop bound derived from cpb_cnt_minus1[i] (the loop index) instead of the sub-layer 0 CPB count cpb_cnt_minus1[0] from the referenced Sequence… | |
| Pendiente de análisis | Media (6.5) | 0.37% | — | Gstreamer Gst-plugins-badAI | 11/6/2026 | 17/6/2026 | An out-of-bounds write vulnerability was found in GStreamer's H.266/VVC PPS picture partition parser in gst-plugins-bad. In the multi-slice-in-tile processing of gst_h266_parser_parse_picture_partition() (gsth266parser.c), the loop iterates without checking that the slice index stays within bounds, writing past three… | |
| Analizada | Alta (7.5) | 0.22% | — | Freedesktop Gst-plugins-goodGstreamerDebian LinuxRedhat Enterprise Linux | 23/3/2026 | 17/6/2026 | An incomplete fix for CVE-2024-47778 allows an out-of-bounds read in gst_wavparse_adtl_chunk() function. The patch added a size validation check lsize + 8 > size, but it does not account for the GST_ROUND_UP_2(lsize) used in the actual offset calculation. When lsize is an odd number, the parser advances more bytes… | |
| Modificada | Alta (7.8) | 0.32% | — | Gstreamer | 16/3/2026 | 15/7/2026 | GStreamer H.266 Codec Parser Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the… | |
| Modificada | Alta (8.8) | 1.2% | — | Gstreamer | 16/3/2026 | 21/7/2026 | GStreamer rtpqdm2depay Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the… | |
| Modificada | Alta (7.8) | 0.32% | — | Gstreamer | 16/3/2026 | 15/7/2026 | GStreamer H.266 Codec Parser Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the… | |
| Modificada | Alta (8.8) | 1.1% | — | Gstreamer | 16/3/2026 | 21/7/2026 | GStreamer rtpqdm2depay Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the… | |
| Modificada | Alta (7.8) | 0.38% | — | Gstreamer | 16/3/2026 | 21/7/2026 | GStreamer JPEG Parser Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the… | |
| Modificada | Alta (7.8) | 0.34% | — | Gstreamer | 16/3/2026 | 15/7/2026 | GStreamer H.266 Codec Parser Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the… | |
| Modificada | Alta (7.8) | 0.34% | — | Gstreamer | 16/3/2026 | 21/7/2026 | GStreamer DVB Subtitles Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the… | |
| Modificada | Alta (7.8) | 0.34% | — | Gstreamer | 16/3/2026 | 21/7/2026 | GStreamer RealMedia Demuxer Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the… | |
| Modificada | Alta (7.8) | 0.35% | — | Gstreamer | 16/3/2026 | 21/7/2026 | GStreamer RIFF Palette Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation.… | |
| Modificada | Alta (7.8) | 0.37% | — | Gstreamer | 16/3/2026 | 21/7/2026 | GStreamer ASF Demuxer Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the… | |
| Analizada | Media (5.6) | 0.48% | — | Gstreamer | 7/8/2025 | 17/6/2026 | In GStreamer through 1.26.1, the subparse plugin's tmplayer_parse_line function may dereference a NULL pointer while parsing a subtitle file, leading to a crash. | |
| Analizada | Media (5.5) | 0.20% | — | Gstreamer | 7/8/2025 | 17/6/2026 | In GStreamer through 1.26.1, the subparse plugin's subrip_unescape_formatting function may dereference a NULL pointer while parsing a subtitle file, leading to a crash. | |
| Analizada | Media (5.6) | 0.29% | — | Gstreamer | 7/8/2025 | 17/6/2026 | In GStreamer through 1.26.1, the subparse plugin's parse_subrip_time function may write data past the bounds of a stack buffer, leading to a crash. | |
| Modificada | Alta (8.1) | 0.65% | — | Gstreamer | 7/8/2025 | 17/6/2026 | In GStreamer through 1.26.1, the isomp4 plugin's qtdemux_parse_trak function may read past the end of a heap buffer while parsing an MP4 file, possibly leading to information disclosure. | |
| Analizada | Media (6.6) | 0.20% | — | Gstreamer | 7/8/2025 | 17/6/2026 | In GStreamer through 1.26.1, the isomp4 plugin's qtdemux_parse_tree function may read past the end of a heap buffer while parsing an MP4 file, leading to information disclosure. | |
| Analizada | Alta (7.8) | 0.36% | — | Gstreamer | 7/7/2025 | 17/6/2026 | GStreamer H266 Codec Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the… | |
| Analizada | Alta (8.8) | 0.85% | — | GstreamerDebian Linux | 22/5/2025 | 17/6/2026 | GStreamer H265 Codec Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the… | |
| Analizada | Alta (7.8) | 0.13% | — | Gstreamer | 22/5/2025 | 17/6/2026 | GStreamer Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of GStreamer. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this… | |
| Modificada | Media (6.8) | 1.0% | — | Gstreamer | 12/12/2024 | 17/6/2026 | GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference vulnerability has been detected in the parse_lrc function within gstsubparse.c. The parse_lrc function calls strchr() to find the character ']' in the string line. The pointer returned by this call is then passed to… | |
| Modificada | Media (5.1) | 0.92% | — | Gstreamer | 12/12/2024 | 17/6/2026 | GStreamer is a library for constructing graphs of media-handling components. An Use-After-Free read vulnerability has been discovered affecting the processing of CodecPrivate elements in Matroska streams. In the GST_MATROSKA_ID_CODECPRIVATE case within the gst_matroska_demux_parse_stream function, a data chunk is… |