Gstreamer Vulnerabilities

Comprehensive security vulnerability database for Gstreamer products

Last updated: Jun 2, 2021
Total CVEs

7

Critical

0

With Exploits

30

Last 30 Days

0

Severity Distribution

Critical0
0%
High23
329%
Medium7
100%
Low0
0%
DescriptionVendor / ProductExploit Status
CVE-2021-35225.5

This vulnerability allows an attacker to potentially read sensitive information from memory by exploiting how GStreamer processes certain ID3v2 tags in media files. To take advantage of this, the attacker needs to craft a malicious media file that includes these specific tags and then convince a user to play it using an affected version of GStreamer.

gstreamergstreamer
Exploit Available
almost 5 years agoJun 2, 2021
CVE-2017-58465.5

This vulnerability allows an attacker to crash a GStreamer application by sending a specially crafted video file that has an unusual number of languages specified. The attacker needs to be able to deliver this malicious video file to the target system for the attack to succeed.

gstreamergstreamer
Exploit Available
about 9 years agoFeb 9, 2017
CVE-2017-58445.5

This vulnerability allows attackers to crash systems running GStreamer by sending them a specially crafted ASF file, leading to a denial of service. The attacker needs to be able to deliver this malicious file to the target system for the exploit to work.

gstreamergstreamer
Exploit Available
about 9 years agoFeb 9, 2017
CVE-2017-58425.5

This vulnerability allows an attacker to crash the GStreamer application by sending a specially crafted SMI file, which can lead to a denial of service. The attacker needs to get the victim to open this malicious file for the exploit to work.

gstreamergstreamer
Exploit Available
about 9 years agoFeb 9, 2017
CVE-2017-58375.5

This vulnerability allows an attacker to crash the GStreamer application by sending a specially crafted video file, leading to a denial of service. The attacker needs to get the victim to open this malicious video file for the exploit to work.

gstreamergstreamer
Exploit Available
about 9 years agoFeb 9, 2017
CVE-2016-101985.5

This vulnerability allows an attacker to crash a system by sending a specially crafted audio file that causes the software to read invalid memory. The attacker needs to get the victim to open this malicious audio file for the exploit to work.

gstreamergstreamer
Exploit Available
about 9 years agoFeb 9, 2017
CVE-2015-07976.8

This vulnerability allows an attacker to crash the application or potentially run harmful code by sending specially crafted H.264 video files to users of certain versions of Firefox and Thunderbird on Linux. It requires the victim to open the malicious video file, which could lead to a denial of service or compromise their system.

gstreamergstreamer
Exploit Available
almost 11 years agoMay 14, 2015

About Gstreamer Security

This page tracks all publicly disclosed security vulnerabilities (CVEs) affecting Gstreamer products. Our database is updated in real-time from the National Vulnerability Database (NVD) and enriched with exploit information from GitHub and other security research sources.

Each CVE listing includes CVSS severity scores, exploit availability status, AI-powered vulnerability summaries, and links to official patches and security advisories.