VYPR

gst-plugins-base

by Gstreamer

CVEs (9)

  • CVE-2017-5848HigFeb 9, 2017
    risk 0.49cvss 7.5epss 0.04

    The gst_ps_demux_parse_psm function in gst/mpegdemux/gstmpegdemux.c in gst-plugins-bad in GStreamer allows remote attackers to cause a denial of service (invalid memory read and crash) via vectors involving PSM parsing.

  • CVE-2017-5839HigFeb 9, 2017
    risk 0.49cvss 7.5epss 0.04

    The gst_riff_create_audio_caps function in gst-libs/gst/riff/riff-media.c in gst-plugins-base in GStreamer before 1.10.3 does not properly limit recursion, which allows remote attackers to cause a denial of service (stack overflow and crash) via vectors involving nested…

  • CVE-2016-9445HigJan 23, 2017
    risk 0.49cvss 7.5epss 0.06

    Integer overflow in the vmnc decoder in the gstreamer allows remote attackers to cause a denial of service (crash) via large width and height values, which triggers a buffer overflow.

  • CVE-2026-53702MedJun 11, 2026
    risk 0.42cvss 6.5epss

    A stack buffer overflow flaw was found in the GStreamer H.265 codec parser library (gst-plugins-bad). When parsing a buffering period SEI message, the parser uses an incorrect loop bound derived from cpb_cnt_minus1[i] (the loop index) instead of the sub-layer 0 CPB count…

  • CVE-2026-53701MedJun 11, 2026
    risk 0.42cvss 6.5epss

    An out-of-bounds write vulnerability was found in GStreamer's H.266/VVC PPS picture partition parser in gst-plugins-bad. In the multi-slice-in-tile processing of gst_h266_parser_parse_picture_partition() (gsth266parser.c), the loop iterates without checking that the slice index…

  • CVE-2017-5837MedFeb 9, 2017
    risk 0.36cvss 5.5epss 0.00

    The gst_riff_create_audio_caps function in gst-libs/gst/riff/riff-media.c in gst-plugins-base in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (floating point exception and crash) via a crafted video file.

  • CVE-2024-47613Dec 11, 2024
    risk 0.00cvss epss 0.00

    GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference vulnerability has been identified in `gst_gdk_pixbuf_dec_flush` within `gstgdkpixbufdec.c`. This function invokes `memcpy`, using `out_pix` as the destination address.…

  • CVE-2021-3185Jan 25, 2021
    risk 0.00cvss epss 0.01

    A flaw was found in the gstreamer h264 component of gst-plugins-bad before v1.18.1 where when parsing a h264 header, an attacker could cause the stack to be smashed, memory corruption and possibly code execution.

  • CVE-2009-0586Mar 14, 2009
    risk 0.00cvss epss 0.02

    Integer overflow in the gst_vorbis_tag_add_coverart function (gst-libs/gst/tag/gstvorbistag.c) in vorbistag in gst-plugins-base (aka gstreamer-plugins-base) before 0.10.23 in GStreamer allows context-dependent attackers to execute arbitrary code via a crafted COVERART tag that…