VYPR

rpm package

almalinux/gstreamer1-plugins-bad-free-devel

pkg:rpm/almalinux/gstreamer1-plugins-bad-free-devel

Vulnerabilities (23)

  • CVE-2026-59692HigJul 9, 2026
    affected < 1.22.12-7.el9_8.3fixed 1.22.12-7.el9_8.3

    A stack buffer overflow vulnerability was found in GStreamer's DTLS plugin. During a DTLS handshake, the peer certificate Subject Distinguished Name is printed into a fixed-size 2048-byte stack buffer without bounds checking. A remote unauthenticated attacker can send a certifica

  • CVE-2026-59691HigJul 9, 2026
    affected < 1.22.12-7.el9_8.3fixed 1.22.12-7.el9_8.3

    A heap buffer overflow vulnerability was found in GStreamer's rfbsrc plugin. When a client connects to a malicious RFB/VNC server that advertises a 16bpp framebuffer and sends Hextile-encoded updates, the Hextile background fill path writes 32-bit pixel values into a buffer alloc

  • CVE-2026-52722HigJun 15, 2026
    affected < 1.26.7-2.el10_2.4fixed 1.26.7-2.el10_2.4

    A signed integer overflow vulnerability was found in GStreamer's VMnc decoder. A crafted VMnc stream with large cursor dimensions can overflow signed integer payload-size arithmetic, bypassing a length check and leading to out-of-bounds reads. A remote attacker could trick a user

  • CVE-2026-52720HigJun 15, 2026
    affected < 1.26.7-2.el10_2.4fixed 1.26.7-2.el10_2.4

    A heap buffer overflow vulnerability was found in GStreamer's librfb (RFB/VNC client). The rectangle bounds check incorrectly validates area rather than individual dimensions, allowing a malicious VNC server to send a rectangle that extends beyond the framebuffer. A remote attack

  • CVE-2026-52719HigJun 15, 2026
    affected < 1.26.7-2.el10_2.4fixed 1.26.7-2.el10_2.4

    An out-of-bounds read vulnerability was found in the VA JPEG decoder in GStreamer's gst-plugins-bad. The JPEG parser reads a segment length value from the bitstream without validating it against available data. A remote attacker could trick a user into opening a specially crafted

  • CVE-2026-52718MedJun 15, 2026
    affected < 1.26.7-2.el10_2.4fixed 1.26.7-2.el10_2.4

    A denial of service vulnerability was found in GStreamer's AV1 codec parser in gst-plugins-bad. The gst_av1_parser_parse_tile_list_obu() function passes a byte count to a bit-reader API that expects a bit count, causing parser desynchronization. A remote attacker could trick a us

  • CVE-2026-3085HigMar 16, 2026
    affected < 1.26.7-2.el10_2fixed 1.26.7-2.el10_2

    GStreamer rtpqdm2depay Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack v

  • CVE-2026-3083HigMar 16, 2026
    affected < 1.26.7-2.el10_2fixed 1.26.7-2.el10_2

    GStreamer rtpqdm2depay Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors

  • CVE-2026-3082HigMar 16, 2026
    affected < 1.26.7-2.el10_2fixed 1.26.7-2.el10_2

    GStreamer JPEG Parser Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack ve

  • CVE-2026-2923HigMar 16, 2026
    affected < 1.26.7-2.el10_2fixed 1.26.7-2.el10_2

    GStreamer DVB Subtitles Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors

  • CVE-2026-2922HigMar 16, 2026
    affected < 1.26.7-2.el10_2fixed 1.26.7-2.el10_2

    GStreamer RealMedia Demuxer Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vec

  • CVE-2026-2921HigMar 16, 2026
    affected < 1.26.7-2.el10_2fixed 1.26.7-2.el10_2

    GStreamer RIFF Palette Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may

  • CVE-2026-2920HigMar 16, 2026
    affected < 1.26.7-2.el10_2fixed 1.26.7-2.el10_2

    GStreamer ASF Demuxer Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack ve

  • CVE-2025-3887HigMay 22, 2025
    affected < 1.22.12-4.el9_6fixed 1.22.12-4.el9_6

    GStreamer H265 Codec Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but a

  • CVE-2024-0444HigJun 7, 2024
    affected < 1.22.12-3.el9fixed 1.22.12-3.el9

    GStreamer AV1 Video Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but at

  • CVE-2024-4453HigMay 22, 2024
    affected < 1.22.12-3.el9fixed 1.22.12-3.el9

    GStreamer EXIF Metadata Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack ve

  • CVE-2023-50186HigMay 3, 2024
    affected < 1.22.1-4.el9fixed 1.22.1-4.el9

    GStreamer AV1 Video Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but at

  • CVE-2023-44446HigMay 3, 2024
    affected < 1.22.1-2.el9_3fixed 1.22.1-2.el9_3

    GStreamer MXF File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors m

  • CVE-2023-44429HigMay 3, 2024
    affected < 1.22.1-2.el9_3fixed 1.22.1-2.el9_3

    GStreamer AV1 Codec Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but att

  • CVE-2023-40476HigMay 3, 2024
    affected < 1.22.1-4.el9fixed 1.22.1-4.el9

    GStreamer H265 Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack

Page 1 of 2