Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
138 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 1.8% | — | GstreamerDebian LinuxRedhat Enterprise Linux | 19/4/2021 | 17/6/2026 | GStreamer before 1.18.4 might cause heap corruption when parsing certain malformed Matroska files. | |
| Modificada | Alta (7.8) | 1.2% | — | GstreamerDebian LinuxRedhat Enterprise Linux | 19/4/2021 | 17/6/2026 | GStreamer before 1.18.4 might access already-freed memory in error code paths when demuxing certain malformed Matroska files. | |
| Modificada | Alta (7.5) | 2.9% | — | Gstreamer Project Gst-rtsp-serverOpensuse Backports SLEOpensuse Leap | 27/3/2020 | 17/6/2026 | An exploitable denial of service vulnerability exists in the GstRTSPAuth functionality of GStreamer/gst-rtsp-server 1.14.5. A specially crafted RTSP setup request can cause a null pointer deference resulting in denial-of-service. An attacker can send a malicious packet to trigger this vulnerability. | |
| Modificada | Alta (8.8) | 5.9% | — | GstreamerDebian LinuxCanonical Ubuntu Linux | 24/4/2019 | 17/6/2026 | GStreamer before 1.16.0 has a heap-based buffer overflow in the RTSP connection parser via a crafted response from a server, potentially allowing remote code execution. | |
| Modificada | Alta (7.5) | 4.4% | — | GstreamerDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux EUS+4 | 9/2/2017 | 17/6/2026 | The gst_ps_demux_parse_psm function in gst/mpegdemux/gstmpegdemux.c in gst-plugins-bad in GStreamer allows remote attackers to cause a denial of service (invalid memory read and crash) via vectors involving PSM parsing. | |
| Modificada | Alta (7.5) | 3.6% | — | GstreamerDebian Linux | 9/2/2017 | 17/6/2026 | The gst_asf_demux_process_ext_content_desc function in gst/asfdemux/gstasfdemux.c in gst-plugins-ugly in GStreamer allows remote attackers to cause a denial of service (out-of-bounds heap read) via vectors involving extended content descriptors. | |
| Modificada | Media (5.5) | 2.0% | — | Gstreamer | 9/2/2017 | 17/6/2026 | The gst_asf_demux_process_ext_stream_props function in gst/asfdemux/gstasfdemux.c in gst-plugins-ugly in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (invalid memory read and crash) via vectors related to the number of languages in a video file. | |
| Modificada | Alta (7.5) | 3.8% | — | Gstreamer | 9/2/2017 | 17/6/2026 | The gst_avi_demux_parse_ncdt function in gst/avi/gstavidemux.c in gst-plugins-good in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (invalid memory read and crash) via a ncdt sub-tag that "goes behind" the surrounding tag. | |
| Modificada | Media (5.5) | 2.5% | — | Gstreamer | 9/2/2017 | 17/6/2026 | The gst_riff_create_audio_caps function in gst-libs/gst/riff/riff-media.c in gst-plugins-base in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (floating point exception and crash) via a crafted ASF file. | |
| Modificada | Alta (7.5) | 3.8% | — | Gstreamer | 9/2/2017 | 17/6/2026 | Multiple use-after-free vulnerabilities in the (1) gst_mini_object_unref, (2) gst_tag_list_unref, and (3) gst_mxf_demux_update_essence_tracks functions in GStreamer before 1.10.3 allow remote attackers to cause a denial of service (crash) via vectors involving stream tags, as demonstrated by 02785736.mxf. | |
| Modificada | Media (5.5) | 2.2% | — | Gstreamer | 9/2/2017 | 17/6/2026 | The html_context_handle_element function in gst/subparse/samiparse.c in gst-plugins-base in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted SMI file, as demonstrated by OneNote_Manager.smi. | |
| Modificada | Alta (7.5) | 3.8% | — | Gstreamer | 9/2/2017 | 17/6/2026 | The gst_avi_demux_parse_ncdt function in gst/avi/gstavidemux.c in gst-plugins-good in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (out-of-bounds heap read) via vectors involving ncdt tags. | |
| Modificada | Alta (7.5) | 4.7% | — | Gstreamer | 9/2/2017 | 17/6/2026 | The qtdemux_parse_samples function in gst/isomp4/qtdemux.c in gst-plugins-good in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (out-of-bounds heap read) via vectors involving the current stts index. | |
| Modificada | Alta (7.5) | 4.5% | — | Gstreamer | 9/2/2017 | 17/6/2026 | The gst_riff_create_audio_caps function in gst-libs/gst/riff/riff-media.c in gst-plugins-base in GStreamer before 1.10.3 does not properly limit recursion, which allows remote attackers to cause a denial of service (stack overflow and crash) via vectors involving nested WAVEFORMATEX. | |
| Modificada | Alta (7.5) | 4.2% | — | Gstreamer | 9/2/2017 | 17/6/2026 | The gst_date_time_new_from_iso8601_string function in gst/gstdatetime.c in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a malformed datetime string. | |
| Modificada | Media (5.5) | 2.5% | — | Gstreamer | 9/2/2017 | 17/6/2026 | The gst_riff_create_audio_caps function in gst-libs/gst/riff/riff-media.c in gst-plugins-base in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (floating point exception and crash) via a crafted video file. | |
| Modificada | Alta (7.5) | 4.2% | — | Gstreamer | 9/2/2017 | 17/6/2026 | The qtdemux_tag_add_str_full function in gst/isomp4/qtdemux.c in gst-plugins-good in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted tag value. | |
| Modificada | Media (5.5) | 2.7% | — | Gstreamer | 9/2/2017 | 17/6/2026 | The gst_aac_parse_sink_setcaps function in gst/audioparsers/gstaacparse.c in gst-plugins-good in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (invalid memory read and crash) via a crafted audio file. | |
| Modificada | Crítica (9.8) | 8.4% | — | GstreamerRedhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux Server+2 | 27/1/2017 | 17/6/2026 | Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstflxdec.c in the FLIC decoder in GStreamer before 1.10.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) by providing a 'write count' that goes beyond the initialized buffer. | |
| Modificada | Crítica (9.8) | 8.9% | — | GstreamerRedhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux Server+2 | 27/1/2017 | 17/6/2026 | Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstflxdec.c in the FLIC decoder in GStreamer before 1.10.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) by providing a 'skip count' that goes beyond initialized buffer. | |
| Modificada | Crítica (9.8) | 8.9% | — | GstreamerRedhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux Server+2 | 27/1/2017 | 17/6/2026 | Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstflxdec.c in the FLIC decoder in GStreamer before 1.10.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via the start_line parameter. | |
| Modificada | Alta (7.8) | 2.8% | — | Gstreamer | 23/1/2017 | 17/6/2026 | The ROM mappings in the NSF decoder in gstreamer 0.10.x allow remote attackers to cause a denial of service (out-of-bounds read or write) and possibly execute arbitrary code via a crafted NSF music file. | |
| Modificada | Alta (7.5) | 3.6% | — | GstreamerRedhat Enterprise Linux DesktopRedhat Enterprise Linux EUSRedhat Enterprise Linux Server+4 | 23/1/2017 | 17/6/2026 | The vmnc decoder in the gstreamer does not initialize the render canvas, which allows remote attackers to obtain sensitive information as demonstrated by thumbnailing a simple 1 frame vmnc movie that does not draw to the allocated render canvas. | |
| Modificada | Alta (7.5) | 4.8% | — | Gstreamer | 23/1/2017 | 17/6/2026 | Integer overflow in the vmnc decoder in the gstreamer allows remote attackers to cause a denial of service (crash) via large width and height values, which triggers a buffer overflow. | |
| Modificada | Media (5.5) | 8.0% | 💥 Exploit | Gstreamer | 13/1/2017 | 17/6/2026 | The _parse_pat function in the mpegts parser in GStreamer before 1.10.2 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted file. |