Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▲ 13 respecto a la semana anterior
Críticas / altas1459▲ 323 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
138 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (4.4) | 0.18% | — | Gstreamer Gst-plugins-goodAI | 11/9/2026 | 16/9/2026 | A flaw was found in GStreamer's gst-plugins-good isomp4 plugin. When processing a specially crafted MP4 or MOV file containing CEA-608 closed-caption data, an integer overflow in 32-bit unsigned arithmetic can bypass a bounds check in the caption parser. This leads to an out-of-bounds heap read of up to 244 bytes,… | |
| Pendiente de análisis | Alta (7.5) | 0.53% | — | GstreamerAI | 3/9/2026 | 21/9/2026 | A NULL pointer dereference flaw was found in GStreamer's RTSP support library. The vulnerability occurs while parsing an Authorization or WWW-Authenticate header that uses Digest authentication. Specially crafted whitespace placement around a parameter's terminator can cause an internal length calculation to… | |
| Analizada | Alta (7.8) | 0.21% | — | Gstreamer | 20/8/2026 | 2/9/2026 | GStreamer rtpsbcdepay Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The… | |
| Analizada | Alta (7.8) | 0.22% | — | Gstreamer | 20/8/2026 | 2/9/2026 | GStreamer PNG File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a… | |
| Analizada | Alta (7.8) | 0.24% | — | Gstreamer | 20/8/2026 | 2/9/2026 | GStreamer OGG File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a… | |
| Analizada | Alta (7.8) | 0.23% | — | Gstreamer | 20/8/2026 | 2/9/2026 | GStreamer MRF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a… | |
| Analizada | Alta (7.8) | 0.21% | — | Gstreamer | 20/8/2026 | 2/9/2026 | GStreamer MRF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious… | |
| En análisis | Media (6.1) | 0.15% | — | GstreamerRedhat Enterprise Linux | 12/8/2026 | 23/9/2026 | A flaw was found in GStreamer gst-plugins-good (avidemux). In gst_avi_demux_riff_parse_vprp(), the number of available gst_riff_vprp_video_field_desc entries is calculated by dividing the remaining buffer size by the attacker-controlled vprp->fields value, rather than by sizeof(gst_riff_vprp_video_field_desc). This… | |
| En análisis | Media (6.6) | 0.15% | — | GstreamerRedhat Enterprise Linux | 12/8/2026 | 23/9/2026 | A flaw was found in GStreamer gst-plugins-good (avidemux). When parsing FUJIFILM metadata in an AVI strd chunk, gst_avi_demux_parse_strd() decrements a remaining-length counter by fixed offsets (98 and 10 bytes) without verifying sufficient data remains. For crafted strd payloads of exactly 106 or 107 bytes, the… | |
| Pendiente de análisis | Alta (7.1) | 0.58% | — | Gstreamer Gst-plugins-uglyAI | 10/8/2026 | 16/9/2026 | Multiple integer overflow and underflow vulnerabilities were found in the GStreamer gst-plugins-ugly ASF demuxer (asfdemux) when parsing header objects from crafted ASF, WMV, or WMA files. Insufficient validation of attacker-controlled length and size values can bypass bounds checks and cause out-of-bounds heap reads.… | |
| Pendiente de análisis | Alta (7.6) | 0.38% | — | Gstreamer Gst-plugins-badAI | 10/8/2026 | 18/9/2026 | A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/DVI ADPCM audio. Insufficient validation of the per-block sample count for multi-channel streams allows a crafted WAV file to cause writes beyond the allocated output buffer. This can lead to… | |
| Pendiente de análisis | Alta (7.5) | 0.96% | — | Gstreamer Gst-plugins-goodAI | 6/8/2026 | 23/9/2026 | A flaw was found in the GStreamer gst-plugins-good package. The rtph264depay and rtph265depay RTP depayloader elements do not enforce a maximum size limit on the reassembly buffer used during fragmented RTP packet processing. A remote, unauthenticated attacker can send a continuous stream of RTP fragments without ever… | |
| Pendiente de análisis | Alta (7.8) | 0.34% | — | GstreamerAI | 29/7/2026 | 30/7/2026 | GStreamer qtdemux Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the… | |
| Pendiente de análisis | Baja (3.3) | 0.17% | — | Gstreamer Gst-plugins-goodAIMatroskaAIWebmAI | 28/7/2026 | 28/7/2026 | A flaw was found in GStreamer's gst-plugins-good. A heap-based out-of-bounds read of 4 bytes can occur when parsing FLAC audio stream headers embedded in a Matroska or WebM container file. The vulnerability is triggered by a boundary check that does not account for the full size of the data being copied, allowing a… | |
| Pendiente de análisis | Alta (7.5) | 1.0% | — | GstreamerAI | 9/7/2026 | 19/8/2026 | A stack buffer overflow vulnerability was found in GStreamer's DTLS plugin. During a DTLS handshake, the peer certificate Subject Distinguished Name is printed into a fixed-size 2048-byte stack buffer without bounds checking. A remote unauthenticated attacker can send a certificate with an oversized Subject DN that… | |
| Pendiente de análisis | Alta (7.1) | 0.60% | — | GstreamerAI | 9/7/2026 | 2/9/2026 | A heap buffer overflow vulnerability was found in GStreamer's rfbsrc plugin. When a client connects to a malicious RFB/VNC server that advertises a 16bpp framebuffer and sends Hextile-encoded updates, the Hextile background fill path writes 32-bit pixel values into a buffer allocated for 16-bit pixels. This type… | |
| Pendiente de análisis | Baja (3.7) | 0.23% | — | Gstreamer WebrtcbinAI | 7/7/2026 | 8/7/2026 | A logic vulnerability was found in GStreamer's webrtcbin component. The _check_sdp_crypto() function contains an inverted boolean condition that causes it to accept remote SDP offers or answers that lack the required a=fingerprint attribute, while incorrectly rejecting those that include it. An attacker with the… | |
| Analizada | Media (4.4) | 0.16% | — | GstreamerRedhat Enterprise Linux | 23/6/2026 | 6/7/2026 | A flaw was found in GStreamer's gst-plugins-bad package. When processing a specially crafted H.264 video file containing malformed MVC or SVC extension slice NAL units, a 1-byte heap out-of-bounds read can occur during parsing. This happens when the parser attempts to check slice boundary information without first… | |
| Analizada | Media (4.3) | 0.39% | — | GstreamerRedhat Enterprise Linux | 23/6/2026 | 1/7/2026 | A flaw was found in the GStreamer gst-plugins-bad package. When processing a malformed H.266/VVC video stream with a crafted aspect ratio indicator value, the H.266 parser performs an out-of-bounds read of up to 8 bytes from adjacent memory. This flaw allows an attacker to craft a malicious H.266 video file or stream… | |
| Pendiente de análisis | Alta (7.6) | 0.70% | — | Gstreamer Gst-plugins-goodAI | 15/6/2026 | 3/8/2026 | A flaw was found in GStreamer's WavPack audio decoder in gst-plugins-good. When processing a specially crafted WavPack file, an integer overflow in the buffer size calculation (4 * block_samples * channels) in gst_wavpack_dec_handle_frame() causes a very small heap allocation. The WavPack library then writes decoded… | |
| Pendiente de análisis | Alta (7.1) | 0.46% | — | Gstreamer Gst-plugins-uglyAI | 15/6/2026 | 8/9/2026 | A flaw was found in GStreamer's RealMedia demuxer in the gst-plugins-ugly package. When processing a RealMedia file containing a specially crafted FILEINFO metadata section, the demuxer parses variable-name and variable-value pairs using re_skip_pascal_string() without validating that offsets remain within the mapped… | |
| Pendiente de análisis | Alta (7.1) | 0.46% | — | Gstreamer Gst-plugins-uglyAI | 15/6/2026 | 5/8/2026 | A vulnerability was found in the GStreamer RealMedia demuxer (gst-plugins-ugly). When processing a RealMedia (.rm) file, the demuxer parses MDPR (media properties) chunks to configure audio streams. For audio stream header versions 4 and 5, the parser reads fields such as codec type, packet size, sample rate, channel… | |
| Pendiente de análisis | Alta (7.1) | 0.74% | — | GstreamerAI | 15/6/2026 | 3/8/2026 | A signed integer overflow vulnerability was found in GStreamer's VMnc decoder. A crafted VMnc stream with large cursor dimensions can overflow signed integer payload-size arithmetic, bypassing a length check and leading to out-of-bounds reads. A remote attacker could trick a user into opening a specially crafted VMnc… | |
| Pendiente de análisis | Media (5.3) | 0.15% | — | Gstreamer PcapparseAI | 15/6/2026 | 17/6/2026 | Multiple out-of-bounds read vulnerabilities were found in GStreamer's pcapparse element. Malformed PCAP records can trigger reads beyond buffer boundaries during IPv4/TCP header parsing. This element is primarily used in debugging pipelines, limiting real-world exposure. A local attacker could trick a user into… | |
| Pendiente de análisis | Alta (8.8) | 1.2% | — | Gstreamer LibrfbAI | 15/6/2026 | 3/8/2026 | A heap buffer overflow vulnerability was found in GStreamer's librfb (RFB/VNC client). The rectangle bounds check incorrectly validates area rather than individual dimensions, allowing a malicious VNC server to send a rectangle that extends beyond the framebuffer. A remote attacker could set up a malicious VNC server… |