Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

GStreamer — Vulnerabilities & Security Advisories 66

Browse all 66 CVE security advisories affecting GStreamer. AI-powered Chinese analysis, POCs, and references for each vulnerability.

GStreamer is an open-source multimedia framework primarily used for constructing graphs of media-handling components, ranging from simple audio playback to complex video editing and streaming applications. Its widespread adoption in Linux-based systems and embedded devices makes it a critical infrastructure component for media processing. Historically, the framework has been susceptible to a variety of vulnerability classes, including buffer overflows, use-after-free errors, and integer overflows, which frequently lead to remote code execution or denial-of-service conditions. With 56 recorded CVEs, these flaws often stem from parsing complex media formats or handling untrusted input data. While no single catastrophic incident has defined its security history, the high volume of vulnerabilities highlights the challenges of maintaining robust memory safety in a C-based codebase. Developers must apply patches diligently to mitigate risks associated with processing maliciously crafted media files.

Found 61 results / 66 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2024-47603 GHSL-2024-251: GStreamer NULL-pointer dereference in Matroska/WebM demuxer — gstreamer CWE-476 5.5 - 2024-12-11
CVE-2024-47602 GHSL-2024-250: Streamer NULL-pointer dereferences and out-of-bounds reads in Matroska/WebM demuxer — gstreamer CWE-476 5.5 - 2024-12-11
CVE-2024-47601 GHSL-2024-249: GStreamer has a NULL-pointer dereference in Matroska/WebM demuxer — gstreamer CWE-476 5.5 - 2024-12-11
CVE-2024-47600 GHSL-2024-248: GStreamer has an OOB-read in format_channel_mask — gstreamer CWE-125 7.1 - 2024-12-11
CVE-2024-47599 GHSL-2024-247: GStreamer Insufficient error handling in JPEG decoder that can lead to NULL-pointer dereferences — gstreamer CWE-476 5.5 - 2024-12-11
CVE-2024-47598 GHSL-2024-246: GStreamer has an OOB-read in qtdemux_merge_sample_table — gstreamer CWE-125 5.5 - 2024-12-11
CVE-2024-47597 GHSL-2024-245: GStreamer has an OOB-read in qtdemux_parse_samples — gstreamer CWE-125 5.5 - 2024-12-11
CVE-2024-47596 GHSL-2024-244: GStreamer has an OOB-read in FOURCC_SMI_ parsing — gstreamer CWE-125 7.8 - 2024-12-11
CVE-2024-47546 GHSL-2024-243: GStreamer has an integer underflow in extract_cc_from_data leading to OOB-read — gstreamer CWE-191 6.1 - 2024-12-11
CVE-2024-47545 GHSL-2024-242: GStreamer has an integer underflow in FOURCC_strf parsing leading to OOB-read — gstreamer CWE-191 7.1 - 2024-12-11
CVE-2024-47544 GHSL-2024-238: GStreamer has NULL-pointer dereferences in MP4/MOV demuxer CENC handling — gstreamer CWE-476 5.5 - 2024-12-11
CVE-2024-47543 GHSL-2024-236: GStreamer has an OOB-read in qtdemux_parse_container — gstreamer CWE-125 7.1 - 2024-12-11
CVE-2024-47542 GHSL-2024-235: GStreamer ID3v2 parser out-of-bounds read and NULL-pointer dereference — gstreamer CWE-476 5.5 - 2024-12-11
CVE-2024-47541 GHSL-2024-228: GStreamer has an out-of-bounds write in SSA subtitle parser — gstreamer CWE-787 7.1 - 2024-12-11
CVE-2024-47540 GHSL-2024-197: GStreamer uses uninitialized stack memory in Matroska/WebM demuxer — gstreamer CWE-457 7.8 - 2024-12-11
CVE-2024-47539 GHSL-2024-195: GStreamer has an OOB-write in convert_to_s334_1a — gstreamer CWE-787 7.8 - 2024-12-11
CVE-2024-47538 GHSL-2024-115: GStreamer has a stack-buffer overflow in vorbis_handle_identification_packet — gstreamer CWE-121 7.8 - 2024-12-11
CVE-2024-47537 GHSL-2024-094: GStreamer has an OOB-write in isomp4/qtdemux.c — gstreamer CWE-787 5.5 - 2024-12-11
CVE-2024-0444 GStreamer AV1 Video Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability — GStreamer CWE-121 7.8 - 2024-06-07
CVE-2024-4453 GStreamer EXIF Metadata Parsing Integer Overflow Remote Code Execution Vulnerability — GStreamer CWE-190 7.8AI High AI 2024-05-22
CVE-2023-50186 GStreamer AV1 Video Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability — GStreamer CWE-121 7.8 - 2024-05-03
CVE-2023-44446 GStreamer MXF File Parsing Use-After-Free Remote Code Execution Vulnerability — GStreamer CWE-416 7.8 - 2024-05-03
CVE-2023-44429 GStreamer AV1 Codec Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability — GStreamer CWE-122 7.8 - 2024-05-03
CVE-2023-40476 GStreamer H265 Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability — GStreamer CWE-121 7.8 - 2024-05-03
CVE-2023-40475 GStreamer MXF File Parsing Integer Overflow Remote Code Execution Vulnerability — GStreamer CWE-190 7.8 - 2024-05-03
CVE-2023-40474 GStreamer MXF File Parsing Integer Overflow Remote Code Execution Vulnerability — GStreamer CWE-190 7.8 - 2024-05-03
CVE-2023-38104 GStreamer RealMedia File Parsing Integer Overflow Remote Code Execution Vulnerability — GStreamer CWE-190 7.8 - 2024-05-03
CVE-2023-38103 GStreamer RealMedia File Parsing Integer Overflow Remote Code Execution Vulnerability — GStreamer CWE-190 7.8 - 2024-05-03
CVE-2023-37329 GStreamer SRT File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability — GStreamer CWE-122 7.8 - 2024-05-03
CVE-2023-37328 GStreamer PGS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability — GStreamer CWE-122 7.8 - 2024-05-03

This page lists every published CVE security advisory associated with GStreamer. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.