Gstreamer Vulnerabilities
Comprehensive security vulnerability database for Gstreamer products
30
0
30
0
Severity Distribution
| Description | Vendor / Product | Exploit Status | |||
|---|---|---|---|---|---|
| CVE-2017-5839 | 7.5 | This vulnerability allows attackers to crash systems running vulnerable versions of GStreamer by sending specially crafted audio files that trigger excessive recursion. To exploit this, the attacker needs to provide a file with nested audio format data, leading to a denial of service. | gstreamergstreamer | Exploit Available | about 9 years agoFeb 9, 2017 |
| CVE-2017-5838 | 7.5 | This vulnerability allows an attacker to crash the GStreamer application by sending it a specially crafted datetime string. It can be exploited remotely, but the attacker needs to find a way to get the application to process their malformed input. | gstreamergstreamer | Exploit Available | about 9 years agoFeb 9, 2017 |
| CVE-2017-5837 | 5.5 | This vulnerability allows an attacker to crash the GStreamer application by sending a specially crafted video file, leading to a denial of service. The attacker needs to get the victim to open this malicious video file for the exploit to work. | gstreamergstreamer | Exploit Available | about 9 years agoFeb 9, 2017 |
| CVE-2016-10199 | 7.5 | This vulnerability allows attackers to crash GStreamer by sending specially crafted media files that contain malicious tag values. It affects versions before 1.10.3 and can lead to a denial of service, meaning users may experience interruptions when trying to play media. | gstreamergstreamer | Exploit Available | about 9 years agoFeb 9, 2017 |
| CVE-2016-10198 | 5.5 | This vulnerability allows an attacker to crash a system by sending a specially crafted audio file that causes the software to read invalid memory. The attacker needs to get the victim to open this malicious audio file for the exploit to work. | gstreamergstreamer | Exploit Available | about 9 years agoFeb 9, 2017 |
| CVE-2016-9447 | 7.8 | This vulnerability allows an attacker to crash the gstreamer application or potentially run harmful code on a victim's system by tricking them into opening a specially crafted NSF music file. It primarily affects users of gstreamer version 0.10.x who play music files without proper security measures in place. | gstreamergstreamer | Exploit Available | about 9 years agoJan 23, 2017 |
| CVE-2016-9446 | 7.5 | This vulnerability allows attackers to access sensitive information by exploiting the gstreamer software's failure to properly initialize a display area when processing certain video files. To take advantage of this flaw, the attacker needs to send a specially crafted video file that doesn't render correctly, potentially revealing private data from the system. | gstreamergstreamer | Exploit Available | about 9 years agoJan 23, 2017 |
| CVE-2016-9445 | 7.5 | This vulnerability allows an attacker to crash systems using GStreamer by sending specially crafted video files with extremely large dimensions. To exploit this, the attacker needs to deliver a malicious video that the GStreamer software attempts to decode. | gstreamergstreamer | Exploit Available | about 9 years agoJan 23, 2017 |
| CVE-2015-0797 | 6.8 | This vulnerability allows an attacker to crash the application or potentially run harmful code by sending specially crafted H.264 video files to users of certain versions of Firefox and Thunderbird on Linux. It requires the victim to open the malicious video file, which could lead to a denial of service or compromise their system. | gstreamergstreamer | Exploit Available | almost 11 years agoMay 14, 2015 |
| CVE-2009-0586 | 7.5 | This vulnerability allows an attacker to run their own malicious code on a system using GStreamer by sending a specially crafted COVERART tag. It requires the attacker to have the ability to provide a manipulated audio file that exploits a flaw in how GStreamer processes certain data. | gstreamergstreamer | Exploit Available | about 17 years agoMar 14, 2009 |
About Gstreamer Security
This page tracks all publicly disclosed security vulnerabilities (CVEs) affecting Gstreamer products. Our database is updated in real-time from the National Vulnerability Database (NVD) and enriched with exploit information from GitHub and other security research sources.
Each CVE listing includes CVSS severity scores, exploit availability status, AI-powered vulnerability summaries, and links to official patches and security advisories.