Search CVE reports
311 – 320 of 38129 results
A flaw was found in GStreamer's RealMedia demuxer in the gst-plugins-ugly package. When processing a RealMedia file containing a specially crafted FILEINFO metadata section, the demuxer parses variable-name and variable-value...
1 affected package
gst-plugins-ugly1.0
| Package | 24.04 LTS |
|---|---|
| gst-plugins-ugly1.0 | Needs evaluation |
A vulnerability was found in the GStreamer RealMedia demuxer (gst-plugins-ugly). When processing a RealMedia (.rm) file, the demuxer parses MDPR (media properties) chunks to configure audio streams. For audio stream header...
1 affected package
gst-plugins-ugly1.0
| Package | 24.04 LTS |
|---|---|
| gst-plugins-ugly1.0 | Needs evaluation |
A signed integer overflow vulnerability was found in GStreamer's VMnc decoder. A crafted VMnc stream with large cursor dimensions can overflow signed integer payload-size arithmetic, bypassing a length check and leading to...
1 affected package
gst-plugins-bad1.0
| Package | 24.04 LTS |
|---|---|
| gst-plugins-bad1.0 | Needs evaluation |
Multiple out-of-bounds read vulnerabilities were found in GStreamer's pcapparse element. Malformed PCAP records can trigger reads beyond buffer boundaries during IPv4/TCP header parsing. This element is primarily used in debugging...
1 affected package
gst-plugins-bad1.0
| Package | 24.04 LTS |
|---|---|
| gst-plugins-bad1.0 | Needs evaluation |
A heap buffer overflow vulnerability was found in GStreamer's librfb (RFB/VNC client). The rectangle bounds check incorrectly validates area rather than individual dimensions, allowing a malicious VNC server to send a rectangle...
1 affected package
gst-plugins-bad1.0
| Package | 24.04 LTS |
|---|---|
| gst-plugins-bad1.0 | Needs evaluation |
An out-of-bounds read vulnerability was found in the VA JPEG decoder in GStreamer's gst-plugins-bad. The JPEG parser reads a segment length value from the bitstream without validating it against available data. A remote attacker...
1 affected package
gst-plugins-bad1.0
| Package | 24.04 LTS |
|---|---|
| gst-plugins-bad1.0 | Needs evaluation |
A denial of service vulnerability was found in GStreamer's AV1 codec parser in gst-plugins-bad. The gst_av1_parser_parse_tile_list_obu() function passes a byte count to a bit-reader API that expects a bit count, causing parser...
1 affected package
gst-plugins-bad1.0
| Package | 24.04 LTS |
|---|---|
| gst-plugins-bad1.0 | Needs evaluation |
A NULL pointer dereference occurs in Roy Marples NetworkConfiguration/dhcpcd 10.3.0 while parsing configuration options. In parse_option() (src/if-options.c:1886), the code performs a member access on a NULL pointer of type...
1 affected package
dhcpcd
| Package | 24.04 LTS |
|---|---|
| dhcpcd | Needs evaluation |
A code injection vulnerability in the wxExecute() function of OpenCPN v5.12.0 allows attackers to execute arbitrary code via embedding shell metacharacters.
1 affected package
opencpn
| Package | 24.04 LTS |
|---|---|
| opencpn | Needs evaluation |
Impact: When a user-configured proxy on webpack-dev-server has a broad context (e.g. /) and ws: true, it also intercepts the dev server's own HMR WebSocket and forwards it to the proxy target. This leaks the browser's cookies and...
2 affected packages
node-webpack, vue.js
| Package | 24.04 LTS |
|---|---|
| node-webpack | Needs evaluation |
| vue.js | Needs evaluation |