VYPR

rpm package

almalinux/gstreamer1-plugins-good-gtk

pkg:rpm/almalinux/gstreamer1-plugins-good-gtk

Vulnerabilities (47)

  • CVE-2026-18299HigAug 20, 2026
    affected < 1.22.12-7.el9_8.8fixed 1.22.12-7.el9_8.8

    GStreamer rtpsbcdepay Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may va

  • CVE-2026-18298HigAug 20, 2026
    affected < 1.26.7-2.el10_2.7fixed 1.26.7-2.el10_2.7

    GStreamer PNG File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. User interaction is required to exploit this vulnerability in that the target mu

  • CVE-2026-18296HigAug 20, 2026
    affected < 1.26.7-2.el10_2.7fixed 1.26.7-2.el10_2.7

    GStreamer MRF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. User interaction is required to exploit this vulnerability in that the target mu

  • CVE-2026-18295HigAug 20, 2026
    affected < 1.22.12-7.el9_8.8fixed 1.22.12-7.el9_8.8

    GStreamer MRF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. User interaction is required to exploit this vulnerability in that the target must visi

  • CVE-2026-73434MedAug 12, 2026
    affected < 1.26.7-2.el10_2.5fixed 1.26.7-2.el10_2.5

    A flaw was found in GStreamer gst-plugins-good (avidemux). In gst_avi_demux_riff_parse_vprp(), the number of available gst_riff_vprp_video_field_desc entries is calculated by dividing the remaining buffer size by the attacker-controlled vprp->fields value, rather than by sizeof(g

  • CVE-2026-73433MedAug 12, 2026
    affected < 1.26.7-2.el10_2.5fixed 1.26.7-2.el10_2.5

    A flaw was found in GStreamer gst-plugins-good (avidemux). When parsing FUJIFILM metadata in an AVI strd chunk, gst_avi_demux_parse_strd() decrements a remaining-length counter by fixed offsets (98 and 10 bytes) without verifying sufficient data remains. For crafted strd payloads

  • CVE-2026-18649HigAug 6, 2026
    affected < 1.26.7-2.el10_2.3fixed 1.26.7-2.el10_2.3

    A flaw was found in the GStreamer gst-plugins-good package. The rtph264depay and rtph265depay RTP depayloader elements do not enforce a maximum size limit on the reassembly buffer used during fragmented RTP packet processing. A remote, unauthenticated attacker can send a continuo

  • CVE-2026-5056HigJul 29, 2026
    affected < 1.26.7-2.el10_2.2fixed 1.26.7-2.el10_2.2

    GStreamer qtdemux Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vecto

  • CVE-2026-53705HigJun 15, 2026
    affected < 1.26.7-2.el10_2.1fixed 1.26.7-2.el10_2.1

    A flaw was found in GStreamer's WavPack audio decoder in gst-plugins-good. When processing a specially crafted WavPack file, an integer overflow in the buffer size calculation (4 * block_samples * channels) in gst_wavpack_dec_handle_frame() causes a very small heap allocation. Th

  • CVE-2026-3085HigMar 16, 2026
    affected < 1.26.7-2.el10_2fixed 1.26.7-2.el10_2

    GStreamer rtpqdm2depay Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack v

  • CVE-2026-3083HigMar 16, 2026
    affected < 1.26.7-2.el10_2fixed 1.26.7-2.el10_2

    GStreamer rtpqdm2depay Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors

  • CVE-2026-3082HigMar 16, 2026
    affected < 1.26.7-2.el10_2fixed 1.26.7-2.el10_2

    GStreamer JPEG Parser Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack ve

  • CVE-2026-2923HigMar 16, 2026
    affected < 1.26.7-2.el10_2fixed 1.26.7-2.el10_2

    GStreamer DVB Subtitles Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors

  • CVE-2026-2922HigMar 16, 2026
    affected < 1.26.7-2.el10_2fixed 1.26.7-2.el10_2

    GStreamer RealMedia Demuxer Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vec

  • CVE-2026-2921HigMar 16, 2026
    affected < 1.26.7-2.el10_2fixed 1.26.7-2.el10_2

    GStreamer RIFF Palette Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may

  • CVE-2026-2920HigMar 16, 2026
    affected < 1.26.7-2.el10_2fixed 1.26.7-2.el10_2

    GStreamer ASF Demuxer Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack ve

  • CVE-2024-47834CriDec 12, 2024
    affected < 1.22.12-4.el9fixed 1.22.12-4.el9

    GStreamer is a library for constructing graphs of media-handling components. An Use-After-Free read vulnerability has been discovered affecting the processing of CodecPrivate elements in Matroska streams. In the GST_MATROSKA_ID_CODECPRIVATE case within the gst_matroska_demux_pars

  • CVE-2024-47778HigDec 12, 2024
    affected < 1.22.12-4.el9fixed 1.22.12-4.el9

    GStreamer is a library for constructing graphs of media-handling components. An OOB-read vulnerability has been discovered in gst_wavparse_adtl_chunk within gstwavparse.c. This vulnerability arises due to insufficient validation of the size parameter, which can exceed the bounds

  • CVE-2024-47777CriDec 12, 2024
    affected < 1.22.12-4.el9fixed 1.22.12-4.el9

    GStreamer is a library for constructing graphs of media-handling components. An OOB-read vulnerability has been identified in the gst_wavparse_smpl_chunk function within gstwavparse.c. This function attempts to read 4 bytes from the data + 12 offset without checking if the size o

  • CVE-2024-47776CriDec 12, 2024
    affected < 1.22.12-4.el9fixed 1.22.12-4.el9

    GStreamer is a library for constructing graphs of media-handling components. An OOB-read has been discovered in gst_wavparse_cue_chunk within gstwavparse.c. The vulnerability happens due to a discrepancy between the size of the data buffer and the size value provided to the funct

Page 1 of 3