Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

GStreamer — Vulnerabilities & Security Advisories 66

Browse all 66 CVE security advisories affecting GStreamer. AI-powered Chinese analysis, POCs, and references for each vulnerability.

GStreamer is an open-source multimedia framework primarily used for constructing graphs of media-handling components, ranging from simple audio playback to complex video editing and streaming applications. Its widespread adoption in Linux-based systems and embedded devices makes it a critical infrastructure component for media processing. Historically, the framework has been susceptible to a variety of vulnerability classes, including buffer overflows, use-after-free errors, and integer overflows, which frequently lead to remote code execution or denial-of-service conditions. With 56 recorded CVEs, these flaws often stem from parsing complex media formats or handling untrusted input data. While no single catastrophic incident has defined its security history, the high volume of vulnerabilities highlights the challenges of maintaining robust memory safety in a C-based codebase. Developers must apply patches diligently to mitigate risks associated with processing maliciously crafted media files.

CVE ID Title CVSS Severity Published
CVE-2024-47613 GHSL-2024-118: GStreamer has a null pointer dereference in gst_gdk_pixbuf_dec_flush — gstreamer CWE-476 7.1 - 2024-12-11
CVE-2024-47615 GHSL-2024-117: GStreamer has an out-of-bounds write in Ogg demuxer — gstreamer CWE-787 7.1 - 2024-12-11
CVE-2024-47607 GHSL-2024-116: Stack-buffer overflow in gst_opus_dec_parse_header — gstreamer CWE-121 7.8 - 2024-12-11
CVE-2024-47606 GHSL-2024-166: GStreamer Integer overflows in MP4/MOV demuxer and memory allocator that can lead to out-of-bounds writes — gstreamer CWE-190 8.4 - 2024-12-11
CVE-2024-47603 GHSL-2024-251: GStreamer NULL-pointer dereference in Matroska/WebM demuxer — gstreamer CWE-476 5.5 - 2024-12-11
CVE-2024-47602 GHSL-2024-250: Streamer NULL-pointer dereferences and out-of-bounds reads in Matroska/WebM demuxer — gstreamer CWE-476 5.5 - 2024-12-11
CVE-2024-47601 GHSL-2024-249: GStreamer has a NULL-pointer dereference in Matroska/WebM demuxer — gstreamer CWE-476 5.5 - 2024-12-11
CVE-2024-47600 GHSL-2024-248: GStreamer has an OOB-read in format_channel_mask — gstreamer CWE-125 7.1 - 2024-12-11
CVE-2024-47599 GHSL-2024-247: GStreamer Insufficient error handling in JPEG decoder that can lead to NULL-pointer dereferences — gstreamer CWE-476 5.5 - 2024-12-11
CVE-2024-47598 GHSL-2024-246: GStreamer has an OOB-read in qtdemux_merge_sample_table — gstreamer CWE-125 5.5 - 2024-12-11
CVE-2024-47597 GHSL-2024-245: GStreamer has an OOB-read in qtdemux_parse_samples — gstreamer CWE-125 5.5 - 2024-12-11
CVE-2024-47596 GHSL-2024-244: GStreamer has an OOB-read in FOURCC_SMI_ parsing — gstreamer CWE-125 7.8 - 2024-12-11
CVE-2024-47546 GHSL-2024-243: GStreamer has an integer underflow in extract_cc_from_data leading to OOB-read — gstreamer CWE-191 6.1 - 2024-12-11
CVE-2024-47545 GHSL-2024-242: GStreamer has an integer underflow in FOURCC_strf parsing leading to OOB-read — gstreamer CWE-191 7.1 - 2024-12-11
CVE-2024-47544 GHSL-2024-238: GStreamer has NULL-pointer dereferences in MP4/MOV demuxer CENC handling — gstreamer CWE-476 5.5 - 2024-12-11
CVE-2024-47543 GHSL-2024-236: GStreamer has an OOB-read in qtdemux_parse_container — gstreamer CWE-125 7.1 - 2024-12-11
CVE-2024-47542 GHSL-2024-235: GStreamer ID3v2 parser out-of-bounds read and NULL-pointer dereference — gstreamer CWE-476 5.5 - 2024-12-11
CVE-2024-47541 GHSL-2024-228: GStreamer has an out-of-bounds write in SSA subtitle parser — gstreamer CWE-787 7.1 - 2024-12-11
CVE-2024-47540 GHSL-2024-197: GStreamer uses uninitialized stack memory in Matroska/WebM demuxer — gstreamer CWE-457 7.8 - 2024-12-11
CVE-2024-47539 GHSL-2024-195: GStreamer has an OOB-write in convert_to_s334_1a — gstreamer CWE-787 7.8 - 2024-12-11
CVE-2024-47538 GHSL-2024-115: GStreamer has a stack-buffer overflow in vorbis_handle_identification_packet — gstreamer CWE-121 7.8 - 2024-12-11
CVE-2024-47537 GHSL-2024-094: GStreamer has an OOB-write in isomp4/qtdemux.c — gstreamer CWE-787 5.5 - 2024-12-11
CVE-2024-40897 ORC 安全漏洞 — ORC 8.6 - 2024-07-26
CVE-2024-0444 GStreamer AV1 Video Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability — GStreamer CWE-121 7.8 - 2024-06-07
CVE-2024-4453 GStreamer EXIF Metadata Parsing Integer Overflow Remote Code Execution Vulnerability — GStreamer CWE-190 7.8AI High AI 2024-05-22
CVE-2023-50186 GStreamer AV1 Video Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability — GStreamer CWE-121 7.8 - 2024-05-03
CVE-2023-44446 GStreamer MXF File Parsing Use-After-Free Remote Code Execution Vulnerability — GStreamer CWE-416 7.8 - 2024-05-03
CVE-2023-44429 GStreamer AV1 Codec Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability — GStreamer CWE-122 7.8 - 2024-05-03
CVE-2023-40476 GStreamer H265 Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability — GStreamer CWE-121 7.8 - 2024-05-03
CVE-2023-40475 GStreamer MXF File Parsing Integer Overflow Remote Code Execution Vulnerability — GStreamer CWE-190 7.8 - 2024-05-03

This page lists every published CVE security advisory associated with GStreamer. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.