Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

gstreamer — Vulnerabilities & Security Advisories 66

All 66 CVE vulnerabilities found in gstreamer, with AI-generated Chinese analysis, references, and POCs.

This page is a vulnerability aggregation resource for the GStreamer multimedia framework, focusing on the Common Weakness Enumeration (CWE) taxonomy and associated security tags. It collects data on known security flaws affecting GStreamer, spanning vulnerability disclosures from its initial public releases through the most recent updates in the current year. By providing a centralized view of these security events, the page allows users to track vendor advisories and security patches issued by the GStreamer maintainers. It enables researchers and developers to understand specific weakness classes that have impacted the framework over time. Furthermore, it offers a comprehensive lookup for the product’s vulnerability history, detailing how specific issues were identified, rated, and resolved. This aggregation supports better risk assessment and secure integration practices by highlighting recurring patterns in GStreamer’s security landscape. The data is structured to facilitate analysis of trend lines in defect types and severity distributions. Users can explore the relationship between different CWE categories and their manifestation within the GStreamer codebase. This resource is intended for security professionals, open-source contributors, and enterprise administrators seeking to audit or harden their multimedia infrastructure. It serves as a reference point for understanding the historical security posture of GStreamer and identifying areas requiring ongoing attention. All entries are sourced from official advisories and reputable security databases to ensure accuracy and relevance for informed decision-making regarding software updates and mitigation strategies.

Vendor: n/a

CVE IDTitleCVSSSeverityPublished
CVE-2024-47598 GHSL-2024-246: GStreamer has an OOB-read in qtdemux_merge_sample_table CWE-125 5.5 -2024-12-11
CVE-2024-47597 GHSL-2024-245: GStreamer has an OOB-read in qtdemux_parse_samples CWE-125 5.5 -2024-12-11
CVE-2024-47596 GHSL-2024-244: GStreamer has an OOB-read in FOURCC_SMI_ parsing CWE-125 7.8 -2024-12-11
CVE-2024-47546 GHSL-2024-243: GStreamer has an integer underflow in extract_cc_from_data leading to OOB-read CWE-191 6.1 -2024-12-11
CVE-2024-47545 GHSL-2024-242: GStreamer has an integer underflow in FOURCC_strf parsing leading to OOB-read CWE-191 7.1 -2024-12-11
CVE-2024-47544 GHSL-2024-238: GStreamer has NULL-pointer dereferences in MP4/MOV demuxer CENC handling CWE-476 5.5 -2024-12-11
CVE-2024-47543 GHSL-2024-236: GStreamer has an OOB-read in qtdemux_parse_container CWE-125 7.1 -2024-12-11
CVE-2024-47542 GHSL-2024-235: GStreamer ID3v2 parser out-of-bounds read and NULL-pointer dereference CWE-476 5.5 -2024-12-11
CVE-2024-47541 GHSL-2024-228: GStreamer has an out-of-bounds write in SSA subtitle parser CWE-787 7.1 -2024-12-11
CVE-2024-47540 GHSL-2024-197: GStreamer uses uninitialized stack memory in Matroska/WebM demuxer CWE-457 7.8 -2024-12-11
CVE-2024-47539 GHSL-2024-195: GStreamer has an OOB-write in convert_to_s334_1a CWE-787 7.8 -2024-12-11
CVE-2024-47538 GHSL-2024-115: GStreamer has a stack-buffer overflow in vorbis_handle_identification_packet CWE-121 7.8 -2024-12-11
CVE-2024-47537 GHSL-2024-094: GStreamer has an OOB-write in isomp4/qtdemux.c CWE-787 5.5 -2024-12-11
CVE-2024-0444 GStreamer AV1 Video Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability CWE-121 7.8 -2024-06-07
CVE-2024-4453 GStreamer EXIF Metadata Parsing Integer Overflow Remote Code Execution Vulnerability CWE-190 7.8AIHighAI2024-05-22
CVE-2023-50186 GStreamer AV1 Video Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability CWE-121 7.8 -2024-05-03
CVE-2023-44446 GStreamer MXF File Parsing Use-After-Free Remote Code Execution Vulnerability CWE-416 7.8 -2024-05-03
CVE-2023-44429 GStreamer AV1 Codec Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability CWE-122 7.8 -2024-05-03
CVE-2023-40476 GStreamer H265 Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability CWE-121 7.8 -2024-05-03
CVE-2023-40474 GStreamer MXF File Parsing Integer Overflow Remote Code Execution Vulnerability CWE-190 7.8 -2024-05-03
CVE-2023-40475 GStreamer MXF File Parsing Integer Overflow Remote Code Execution Vulnerability CWE-190 7.8 -2024-05-03
CVE-2023-38104 GStreamer RealMedia File Parsing Integer Overflow Remote Code Execution Vulnerability CWE-190 7.8 -2024-05-03
CVE-2023-38103 GStreamer RealMedia File Parsing Integer Overflow Remote Code Execution Vulnerability CWE-190 7.8 -2024-05-03
CVE-2023-37329 GStreamer SRT File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability CWE-122 7.8 -2024-05-03
CVE-2023-37328 GStreamer PGS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability CWE-122 7.8 -2024-05-03
CVE-2023-37327 GStreamer FLAC File Parsing Integer Overflow Remote Code Execution Vulnerability CWE-190 7.8 -2024-05-03
CVE-2022-1924 GStreamer 输入验证错误漏洞 CWE-122 7.8 -2022-07-19
CVE-2022-1923 GStreamer 输入验证错误漏洞 CWE-122 7.8 -2022-07-19
CVE-2022-2122 GStreamer 输入验证错误漏洞 CWE-122 7.8 -2022-07-19
CVE-2022-1925 GStreamer 输入验证错误漏洞 CWE-122 7.8 -2022-07-19

All 66 known CVE vulnerabilities affecting gstreamer with full Chinese analysis, references, and POCs where available.