Search CVE reports


Toggle filters

1 – 9 of 9 results


CVE-2026-19389

Medium priority
Fixed

Multiple integer overflow and underflow vulnerabilities were found in the GStreamer gst-plugins-ugly ASF demuxer (asfdemux) when parsing header objects from crafted ASF, WMV, or WMA files. Insufficient validation...

1 affected package

gst-plugins-ugly1.0

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gst-plugins-ugly1.0 Fixed Fixed Fixed Fixed Fixed
Show less packages

CVE-2026-53704

Medium priority

Some fixes available 6 of 7

A flaw was found in GStreamer's RealMedia demuxer in the gst-plugins-ugly package. When processing a RealMedia file containing a specially crafted FILEINFO metadata section, the demuxer parses variable-name and variable-value...

1 affected package

gst-plugins-ugly1.0

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gst-plugins-ugly1.0 Fixed Fixed Fixed Fixed Fixed
Show less packages

CVE-2026-53703

Medium priority

Some fixes available 6 of 7

A vulnerability was found in the GStreamer RealMedia demuxer (gst-plugins-ugly). When processing a RealMedia (.rm) file, the demuxer parses MDPR (media properties) chunks to configure audio streams. For audio stream header...

1 affected package

gst-plugins-ugly1.0

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gst-plugins-ugly1.0 Fixed Fixed Fixed Fixed Fixed
Show less packages

CVE-2026-2922

Medium priority

Some fixes available 5 of 6

GStreamer RealMedia Demuxer Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is...

1 affected package

gst-plugins-ugly1.0

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gst-plugins-ugly1.0 Not affected Fixed Fixed Fixed Fixed
Show less packages

CVE-2026-2920

Medium priority

Some fixes available 5 of 6

GStreamer ASF Demuxer Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is...

1 affected package

gst-plugins-ugly1.0

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gst-plugins-ugly1.0 Not affected Fixed Fixed Fixed Fixed
Show less packages

CVE-2023-38104

Medium priority

Some fixes available 4 of 5

GStreamer RealMedia File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is...

2 affected packages

gst-plugins-ugly1.0, gst-plugins-ugly0.10

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gst-plugins-ugly1.0 Not affected Not affected Fixed Fixed Fixed
gst-plugins-ugly0.10 Not in release Not in release Not in release Not in release Ignored
Show less packages

CVE-2023-38103

Medium priority

Some fixes available 4 of 5

GStreamer RealMedia File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is...

2 affected packages

gst-plugins-ugly1.0, gst-plugins-ugly0.10

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gst-plugins-ugly1.0 Not affected Not affected Fixed Fixed Fixed
gst-plugins-ugly0.10 Not in release Not in release Not in release Not in release Ignored
Show less packages

CVE-2017-5847

Low priority

Some fixes available 1 of 6

The gst_asf_demux_process_ext_content_desc function in gst/asfdemux/gstasfdemux.c in gst-plugins-ugly in GStreamer allows remote attackers to cause a denial of service (out-of-bounds heap read) via vectors involving extended...

2 affected packages

gst-plugins-ugly1.0, gst-plugins-ugly0.10

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gst-plugins-ugly1.0 Not affected Not affected Not affected Not affected Not affected
gst-plugins-ugly0.10 Not in release Not in release Not in release Not in release Not in release
Show less packages

CVE-2017-5846

Low priority

Some fixes available 1 of 4

The gst_asf_demux_process_ext_stream_props function in gst/asfdemux/gstasfdemux.c in gst-plugins-ugly in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (invalid memory read and crash) via vectors...

2 affected packages

gst-plugins-ugly1.0, gst-plugins-ugly0.10

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gst-plugins-ugly1.0 Not affected Not affected Not affected Not affected Not affected
gst-plugins-ugly0.10 Not in release Not in release Not in release Not in release Not in release
Show less packages