Gstreamer Vulnerabilities

Comprehensive security vulnerability database for Gstreamer products

Last updated: Jul 19, 2022
Total CVEs

30

Critical

0

With Exploits

30

Last 30 Days

0

Severity Distribution

Critical0
0%
High23
77%
Medium7
23%
Low0
0%
DescriptionVendor / ProductExploit Status
CVE-2022-21227.8

This vulnerability allows an attacker to crash a system or potentially take control of it by exploiting a flaw in the way GStreamer processes certain compressed video files. It requires the attacker to trick the system into handling a specially crafted file, which could lead to serious issues depending on the operating system and its libraries.

gstreamergstreamer
Exploit Available
over 3 years agoJul 19, 2022
CVE-2022-19257.8

This vulnerability allows an attacker to potentially crash a system or execute malicious code by exploiting a flaw in how GStreamer processes certain video files. While the risk of triggering this issue is limited due to size restrictions in one part of the software, the lack of checks in another part means that specially crafted video files could still lead to serious problems.

gstreamergstreamer
Exploit Available
over 3 years agoJul 19, 2022
CVE-2022-19247.8

This vulnerability allows an attacker to potentially crash a system or overwrite memory when processing certain video files, which could lead to further exploitation. The impact depends on the specific system libraries and operating system in use; on some systems, it might just cause a crash, while on others, it could allow an attacker to manipulate memory.

gstreamergstreamer
Exploit Available
over 3 years agoJul 19, 2022
CVE-2022-19237.8

This vulnerability allows an attacker to crash an application or potentially overwrite memory when it processes certain MKV files using bzip compression. The impact depends on the system's configuration; if it uses specific memory management techniques, it may only cause a crash, but in other cases, it could lead to more serious memory corruption issues.

gstreamergstreamer
Exploit Available
over 3 years agoJul 19, 2022
CVE-2022-19227.8

This vulnerability allows an attacker to crash the application or potentially overwrite memory, which could lead to further exploitation, by sending specially crafted MKV files for processing. The impact varies based on the system's memory management; if the system uses certain memory handling techniques, it may only crash, but in other cases, it could allow an attacker to manipulate memory directly.

gstreamergstreamer
Exploit Available
over 3 years agoJul 19, 2022
CVE-2022-19217.8

This vulnerability allows an attacker to run their own code on a system by exploiting a flaw in how certain AVI files are processed, which can lead to overwriting memory. To take advantage of this, the attacker needs to get the victim to open a specially crafted AVI file using GStreamer.

gstreamergstreamer
Exploit Available
over 3 years agoJul 19, 2022
CVE-2022-19207.8

This vulnerability allows an attacker to execute arbitrary code on a system by exploiting a flaw in how certain video files are processed. It requires the attacker to get the victim to open a specially crafted Matroska file, which can lead to serious security breaches.

gstreamergstreamer
Exploit Available
over 3 years agoJul 19, 2022
CVE-2021-35225.5

This vulnerability allows an attacker to potentially read sensitive information from memory by exploiting how GStreamer processes certain ID3v2 tags in media files. To take advantage of this, the attacker needs to craft a malicious media file that includes these specific tags and then convince a user to play it using an affected version of GStreamer.

gstreamergstreamer
Exploit Available
almost 5 years agoJun 2, 2021
CVE-2021-34987.8

This vulnerability allows an attacker to crash a system or potentially run malicious code by tricking it into processing specially crafted Matroska files. It affects versions of GStreamer before 1.18.4, so users need to ensure they are using an updated version to avoid this risk.

gstreamergstreamer
Exploit Available
almost 5 years agoApr 19, 2021
CVE-2021-34977.8

This vulnerability allows an attacker to potentially crash a system or execute malicious code by tricking it into processing specially crafted Matroska files. It occurs when the GStreamer software tries to handle errors in these files, leading to access of memory that has already been freed, which can happen if the software is not updated to the latest version.

gstreamergstreamer
Exploit Available
almost 5 years agoApr 19, 2021
CVE-2019-99288.8

This vulnerability allows an attacker to run malicious code on a victim's system by sending a specially crafted response to a GStreamer application. It requires the victim to connect to a compromised RTSP server that exploits this flaw in GStreamer versions before 1.16.0.

gstreamergstreamer
Exploit Available
almost 7 years agoApr 24, 2019
CVE-2017-58487.5

This vulnerability allows attackers to crash GStreamer applications by sending specially crafted data that triggers an invalid memory read during the parsing of program-specific information. To exploit this, the attacker needs to be able to send malicious input to the affected application using GStreamer.

gstreamergstreamer
Exploit Available
about 9 years agoFeb 9, 2017
CVE-2017-58477.5

This vulnerability allows attackers to crash the GStreamer application by exploiting a flaw in how it processes certain media files, specifically those with extended content descriptors. To successfully launch this attack, the attacker needs to send a specially crafted media file to the target system.

gstreamergstreamer
Exploit Available
about 9 years agoFeb 9, 2017
CVE-2017-58465.5

This vulnerability allows an attacker to crash a GStreamer application by sending a specially crafted video file that has an unusual number of languages specified. The attacker needs to be able to deliver this malicious video file to the target system for the attack to succeed.

gstreamergstreamer
Exploit Available
about 9 years agoFeb 9, 2017
CVE-2017-58457.5

This vulnerability allows an attacker to crash a system running GStreamer by sending a specially crafted AVI file that causes the software to read invalid memory. The attack requires the victim to open the malicious file, leading to a denial of service.

gstreamergstreamer
Exploit Available
about 9 years agoFeb 9, 2017
CVE-2017-58445.5

This vulnerability allows attackers to crash systems running GStreamer by sending them a specially crafted ASF file, leading to a denial of service. The attacker needs to be able to deliver this malicious file to the target system for the exploit to work.

gstreamergstreamer
Exploit Available
about 9 years agoFeb 9, 2017
CVE-2017-58437.5

This vulnerability allows attackers to crash applications using GStreamer by exploiting flaws in how the software handles certain media stream tags. It can be triggered remotely, meaning that users don’t need to be directly connected to the attacker to be affected.

gstreamergstreamer
Exploit Available
about 9 years agoFeb 9, 2017
CVE-2017-58425.5

This vulnerability allows an attacker to crash the GStreamer application by sending a specially crafted SMI file, which can lead to a denial of service. The attacker needs to get the victim to open this malicious file for the exploit to work.

gstreamergstreamer
Exploit Available
about 9 years agoFeb 9, 2017
CVE-2017-58417.5

This vulnerability allows attackers to crash applications using GStreamer by exploiting a flaw in how certain video files are processed, specifically those with ncdt tags. To trigger this issue, an attacker needs to send a specially crafted video file to the target system.

gstreamergstreamer
Exploit Available
about 9 years agoFeb 9, 2017
CVE-2017-58407.5

This vulnerability allows an attacker to crash applications using GStreamer by exploiting a flaw in how the software processes certain media files, leading to a denial of service. It can be triggered remotely if the attacker can send specially crafted media files to the affected system.

gstreamergstreamer
Exploit Available
about 9 years agoFeb 9, 2017
Showing 1 to 20 of 30 results

About Gstreamer Security

This page tracks all publicly disclosed security vulnerabilities (CVEs) affecting Gstreamer products. Our database is updated in real-time from the National Vulnerability Database (NVD) and enriched with exploit information from GitHub and other security research sources.

Each CVE listing includes CVSS severity scores, exploit availability status, AI-powered vulnerability summaries, and links to official patches and security advisories.