VulnSea

gstreamer1-plugins-bad-free vulnerabilities

CVEs whose affected-version data names the gstreamer1-plugins-bad-free package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

6 CVEsRSS

CVE-2026-19389High· 7.1
1mo ago

Multiple integer overflow and underflow vulnerabilities were found in the GStreamer gst-plugins-ugly ASF demuxer (asfdemux) when parsing header objects from crafted ASF, WMV, or WMA files

Multiple integer overflow and underflow vulnerabilities were found in the GStreamer gst-plugins-ugly ASF demuxer (asfdemux) when parsing header objects from crafted ASF, WMV, or WMA files. Insufficient validation of attacker-controlled l…

TwilightRed Hat · gstreamer1-plugins-ugly-freeEPSS 0.41%via NVD
CVE-2026-19387High· 7.6
1mo ago

A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/DVI ADPCM audio

A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/DVI ADPCM audio. Insufficient validation of the per-block sample count for multi-channel streams allows a crafted WAV …

TwilightRed Hat · gstreamer1-plugins-bad-freeEPSS 0.30%via NVD
CVE-2026-59692High· 7.5
2mo ago

A stack buffer overflow vulnerability was found in GStreamer's DTLS plugin

A stack buffer overflow vulnerability was found in GStreamer's DTLS plugin. During a DTLS handshake, the peer certificate Subject Distinguished Name is printed into a fixed-size 2048-byte stack buffer without bounds checking. A remote un…

TwilightRed Hat · gstreamer1-plugins-bad-freeEPSS 0.58%via NVD
CVE-2026-59691High· 7.1
2mo ago

A heap buffer overflow vulnerability was found in GStreamer's rfbsrc plugin

A heap buffer overflow vulnerability was found in GStreamer's rfbsrc plugin. When a client connects to a malicious RFB/VNC server that advertises a 16bpp framebuffer and sends Hextile-encoded updates, the Hextile background fill path wri…

TwilightRed Hat · gstreamer1-plugins-bad-freeEPSS 0.33%via NVD
CVE-2026-14935Low· 3.7
2mo ago

Gstreamer1-plugins-bad-free: gstreamer: webrtcbin accepts remote sdp without a=fingerprint due to inverted presence check

A logic vulnerability was found in GStreamer's webrtcbin component. The _check_sdp_crypto() function contains an inverted boolean condition that causes it to accept remote SDP offers or answers that lack the required a=fingerprint attrib…

SunlitRed Hat · gstreamer1-plugins-bad-freeEPSS 0.23%via CVEORG
CVE-2026-12891Medium· 4.3
3mo ago

Gstreamer1-plugins-bad-free: gstreamer1-plugins-bad: global buffer overflow (oob read) in h.266/vvc vui parameter parser

A flaw was found in the GStreamer gst-plugins-bad package. When processing a malformed H.266/VVC video stream with a crafted aspect ratio indicator value, the H.266 parser performs an out-of-bounds read of up to 8 bytes from adjacent mem…

SunlitRed Hat · gstreamer1-plugins-bad-freeEPSS 0.27%via CVEORG
gstreamer1-plugins-bad-free vulnerabilities (CVEs) · VulnSea