Gstreamer Vulnerabilities
Comprehensive security vulnerability database for Gstreamer products
7
0
30
0
Severity Distribution
| Description | Vendor / Product | Exploit Status | |||
|---|---|---|---|---|---|
| CVE-2021-3522 | 5.5 | This vulnerability allows an attacker to potentially read sensitive information from memory by exploiting how GStreamer processes certain ID3v2 tags in media files. To take advantage of this, the attacker needs to craft a malicious media file that includes these specific tags and then convince a user to play it using an affected version of GStreamer. | gstreamergstreamer | Exploit Available | almost 5 years agoJun 2, 2021 |
| CVE-2017-5846 | 5.5 | This vulnerability allows an attacker to crash a GStreamer application by sending a specially crafted video file that has an unusual number of languages specified. The attacker needs to be able to deliver this malicious video file to the target system for the attack to succeed. | gstreamergstreamer | Exploit Available | about 9 years agoFeb 9, 2017 |
| CVE-2017-5844 | 5.5 | This vulnerability allows attackers to crash systems running GStreamer by sending them a specially crafted ASF file, leading to a denial of service. The attacker needs to be able to deliver this malicious file to the target system for the exploit to work. | gstreamergstreamer | Exploit Available | about 9 years agoFeb 9, 2017 |
| CVE-2017-5842 | 5.5 | This vulnerability allows an attacker to crash the GStreamer application by sending a specially crafted SMI file, which can lead to a denial of service. The attacker needs to get the victim to open this malicious file for the exploit to work. | gstreamergstreamer | Exploit Available | about 9 years agoFeb 9, 2017 |
| CVE-2017-5837 | 5.5 | This vulnerability allows an attacker to crash the GStreamer application by sending a specially crafted video file, leading to a denial of service. The attacker needs to get the victim to open this malicious video file for the exploit to work. | gstreamergstreamer | Exploit Available | about 9 years agoFeb 9, 2017 |
| CVE-2016-10198 | 5.5 | This vulnerability allows an attacker to crash a system by sending a specially crafted audio file that causes the software to read invalid memory. The attacker needs to get the victim to open this malicious audio file for the exploit to work. | gstreamergstreamer | Exploit Available | about 9 years agoFeb 9, 2017 |
| CVE-2015-0797 | 6.8 | This vulnerability allows an attacker to crash the application or potentially run harmful code by sending specially crafted H.264 video files to users of certain versions of Firefox and Thunderbird on Linux. It requires the victim to open the malicious video file, which could lead to a denial of service or compromise their system. | gstreamergstreamer | Exploit Available | almost 11 years agoMay 14, 2015 |
About Gstreamer Security
This page tracks all publicly disclosed security vulnerabilities (CVEs) affecting Gstreamer products. Our database is updated in real-time from the National Vulnerability Database (NVD) and enriched with exploit information from GitHub and other security research sources.
Each CVE listing includes CVSS severity scores, exploit availability status, AI-powered vulnerability summaries, and links to official patches and security advisories.