rpm package
almalinux/gstreamer1-plugins-ugly-free
pkg:rpm/almalinux/gstreamer1-plugins-ugly-free
Vulnerabilities (12)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-53704 | Hig | 7.1 | < 1.22.12-6.el9_8.1 | 1.22.12-6.el9_8.1 | Jun 15, 2026 | A flaw was found in GStreamer's RealMedia demuxer in the gst-plugins-ugly package. When processing a RealMedia file containing a specially crafted FILEINFO metadata section, the demuxer parses variable-name and variable-value pairs using re_skip_pascal_string() without validating | |
| CVE-2026-53703 | Hig | 7.1 | < 1.26.7-2.el10_2.1 | 1.26.7-2.el10_2.1 | Jun 15, 2026 | A vulnerability was found in the GStreamer RealMedia demuxer (gst-plugins-ugly). When processing a RealMedia (.rm) file, the demuxer parses MDPR (media properties) chunks to configure audio streams. For audio stream header versions 4 and 5, the parser reads fields such as codec t | |
| CVE-2026-3085 | Hig | 8.8 | < 1.26.7-2.el10_2 | 1.26.7-2.el10_2 | Mar 16, 2026 | GStreamer rtpqdm2depay Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack v | |
| CVE-2026-3083 | Hig | 8.8 | < 1.26.7-2.el10_2 | 1.26.7-2.el10_2 | Mar 16, 2026 | GStreamer rtpqdm2depay Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors | |
| CVE-2026-3082 | Hig | 7.8 | < 1.26.7-2.el10_2 | 1.26.7-2.el10_2 | Mar 16, 2026 | GStreamer JPEG Parser Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack ve | |
| CVE-2026-2923 | Hig | 7.8 | < 1.26.7-2.el10_2 | 1.26.7-2.el10_2 | Mar 16, 2026 | GStreamer DVB Subtitles Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors | |
| CVE-2026-2922 | Hig | 7.8 | < 1.26.7-2.el10_2 | 1.26.7-2.el10_2 | Mar 16, 2026 | GStreamer RealMedia Demuxer Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vec | |
| CVE-2026-2921 | Hig | 7.8 | < 1.26.7-2.el10_2 | 1.26.7-2.el10_2 | Mar 16, 2026 | GStreamer RIFF Palette Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may | |
| CVE-2026-2920 | Hig | 7.8 | < 1.26.7-2.el10_2 | 1.26.7-2.el10_2 | Mar 16, 2026 | GStreamer ASF Demuxer Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack ve | |
| CVE-2024-0444 | Hig | 8.8 | < 1.22.12-3.el9 | 1.22.12-3.el9 | Jun 7, 2024 | GStreamer AV1 Video Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but at | |
| CVE-2024-4453 | Hig | 7.8 | < 1.22.12-3.el9 | 1.22.12-3.el9 | May 22, 2024 | GStreamer EXIF Metadata Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack ve | |
| CVE-2018-7263 | Cri | 9.8 | < 1.16.1-1.el8 | 1.16.1-1.el8 | Feb 20, 2018 | The mad_decoder_run() function in decoder.c in Underbit libmad through 0.15.1b allows remote attackers to cause a denial of service (SIGABRT because of double free or corruption) or possibly have unspecified other impact via a crafted file. NOTE: this may overlap CVE-2017-11552. |
- affected < 1.22.12-6.el9_8.1fixed 1.22.12-6.el9_8.1
A flaw was found in GStreamer's RealMedia demuxer in the gst-plugins-ugly package. When processing a RealMedia file containing a specially crafted FILEINFO metadata section, the demuxer parses variable-name and variable-value pairs using re_skip_pascal_string() without validating
- affected < 1.26.7-2.el10_2.1fixed 1.26.7-2.el10_2.1
A vulnerability was found in the GStreamer RealMedia demuxer (gst-plugins-ugly). When processing a RealMedia (.rm) file, the demuxer parses MDPR (media properties) chunks to configure audio streams. For audio stream header versions 4 and 5, the parser reads fields such as codec t
- affected < 1.26.7-2.el10_2fixed 1.26.7-2.el10_2
GStreamer rtpqdm2depay Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack v
- affected < 1.26.7-2.el10_2fixed 1.26.7-2.el10_2
GStreamer rtpqdm2depay Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors
- affected < 1.26.7-2.el10_2fixed 1.26.7-2.el10_2
GStreamer JPEG Parser Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack ve
- affected < 1.26.7-2.el10_2fixed 1.26.7-2.el10_2
GStreamer DVB Subtitles Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors
- affected < 1.26.7-2.el10_2fixed 1.26.7-2.el10_2
GStreamer RealMedia Demuxer Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vec
- affected < 1.26.7-2.el10_2fixed 1.26.7-2.el10_2
GStreamer RIFF Palette Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may
- affected < 1.26.7-2.el10_2fixed 1.26.7-2.el10_2
GStreamer ASF Demuxer Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack ve
- affected < 1.22.12-3.el9fixed 1.22.12-3.el9
GStreamer AV1 Video Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but at
- affected < 1.22.12-3.el9fixed 1.22.12-3.el9
GStreamer EXIF Metadata Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack ve
- affected < 1.16.1-1.el8fixed 1.16.1-1.el8
The mad_decoder_run() function in decoder.c in Underbit libmad through 0.15.1b allows remote attackers to cause a denial of service (SIGABRT because of double free or corruption) or possibly have unspecified other impact via a crafted file. NOTE: this may overlap CVE-2017-11552.