Search CVE reports


Toggle filters

311 – 320 of 38129 results

Status is adjusted based on your filters.


CVE-2026-53704

Medium priority
Needs evaluation

A flaw was found in GStreamer's RealMedia demuxer in the gst-plugins-ugly package. When processing a RealMedia file containing a specially crafted FILEINFO metadata section, the demuxer parses variable-name and variable-value...

1 affected package

gst-plugins-ugly1.0

Package 24.04 LTS
gst-plugins-ugly1.0 Needs evaluation
Show less packages

CVE-2026-53703

Medium priority
Needs evaluation

A vulnerability was found in the GStreamer RealMedia demuxer (gst-plugins-ugly). When processing a RealMedia (.rm) file, the demuxer parses MDPR (media properties) chunks to configure audio streams. For audio stream header...

1 affected package

gst-plugins-ugly1.0

Package 24.04 LTS
gst-plugins-ugly1.0 Needs evaluation
Show less packages

CVE-2026-52722

Medium priority
Needs evaluation

A signed integer overflow vulnerability was found in GStreamer's VMnc decoder. A crafted VMnc stream with large cursor dimensions can overflow signed integer payload-size arithmetic, bypassing a length check and leading to...

1 affected package

gst-plugins-bad1.0

Package 24.04 LTS
gst-plugins-bad1.0 Needs evaluation
Show less packages

CVE-2026-52721

Medium priority
Needs evaluation

Multiple out-of-bounds read vulnerabilities were found in GStreamer's pcapparse element. Malformed PCAP records can trigger reads beyond buffer boundaries during IPv4/TCP header parsing. This element is primarily used in debugging...

1 affected package

gst-plugins-bad1.0

Package 24.04 LTS
gst-plugins-bad1.0 Needs evaluation
Show less packages

CVE-2026-52720

Medium priority
Needs evaluation

A heap buffer overflow vulnerability was found in GStreamer's librfb (RFB/VNC client). The rectangle bounds check incorrectly validates area rather than individual dimensions, allowing a malicious VNC server to send a rectangle...

1 affected package

gst-plugins-bad1.0

Package 24.04 LTS
gst-plugins-bad1.0 Needs evaluation
Show less packages

CVE-2026-52719

Medium priority
Needs evaluation

An out-of-bounds read vulnerability was found in the VA JPEG decoder in GStreamer's gst-plugins-bad. The JPEG parser reads a segment length value from the bitstream without validating it against available data. A remote attacker...

1 affected package

gst-plugins-bad1.0

Package 24.04 LTS
gst-plugins-bad1.0 Needs evaluation
Show less packages

CVE-2026-52718

Medium priority
Needs evaluation

A denial of service vulnerability was found in GStreamer's AV1 codec parser in gst-plugins-bad. The gst_av1_parser_parse_tile_list_obu() function passes a byte count to a bit-reader API that expects a bit count, causing parser...

1 affected package

gst-plugins-bad1.0

Package 24.04 LTS
gst-plugins-bad1.0 Needs evaluation
Show less packages

CVE-2025-70102

Medium priority
Needs evaluation

A NULL pointer dereference occurs in Roy Marples NetworkConfiguration/dhcpcd 10.3.0 while parsing configuration options. In parse_option() (src/if-options.c:1886), the code performs a member access on a NULL pointer of type...

1 affected package

dhcpcd

Package 24.04 LTS
dhcpcd Needs evaluation
Show less packages

CVE-2025-56814

Medium priority
Needs evaluation

A code injection vulnerability in the wxExecute() function of OpenCPN v5.12.0 allows attackers to execute arbitrary code via embedding shell metacharacters.

1 affected package

opencpn

Package 24.04 LTS
opencpn Needs evaluation
Show less packages

CVE-2026-9595

Medium priority
Needs evaluation

Impact: When a user-configured proxy on webpack-dev-server has a broad context (e.g. /) and ws: true, it also intercepts the dev server's own HMR WebSocket and forwards it to the proxy target. This leaks the browser's cookies and...

2 affected packages

node-webpack, vue.js

Package 24.04 LTS
node-webpack Needs evaluation
vue.js Needs evaluation
Show less packages