gstreamer CVE Vulnerabilities & Metrics

Focus on gstreamer vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About gstreamer Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with gstreamer. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total gstreamer CVEs: 11
Earliest CVE date: 02 Feb 2009, 19:30 UTC
Latest CVE date: 26 Jul 2024, 06:15 UTC

Latest CVE reference: CVE-2024-40897

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 1

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical gstreamer CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 6.28

Max CVSS: 9.3

Critical CVEs (≥9): 4

CVSS Range vs. Count

Range Count
0.0-3.9 1
4.0-6.9 8
7.0-8.9 3
9.0-10.0 4

CVSS Distribution Chart

Top 5 Highest CVSS gstreamer CVEs

These are the five CVEs with the highest CVSS scores for gstreamer, sorted by severity first and recency.

All CVEs for gstreamer

CVE-2024-40897 gstreamer vulnerability CVSS: 0 26 Jul 2024, 06:15 UTC

Stack-based buffer overflow vulnerability exists in orcparse.c of ORC versions prior to 0.4.39. If a developer is tricked to process a specially crafted file with the affected ORC compiler, an arbitrary code may be executed on the developer's build environment. This may lead to compromise of developer machines or CI build environments.

CVE-2016-9636 gstreamer vulnerability CVSS: 7.5 27 Jan 2017, 22:59 UTC

Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstflxdec.c in the FLIC decoder in GStreamer before 1.10.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) by providing a 'write count' that goes beyond the initialized buffer.

CVE-2016-9635 gstreamer vulnerability CVSS: 7.5 27 Jan 2017, 22:59 UTC

Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstflxdec.c in the FLIC decoder in GStreamer before 1.10.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) by providing a 'skip count' that goes beyond initialized buffer.

CVE-2016-9634 gstreamer vulnerability CVSS: 7.5 27 Jan 2017, 22:59 UTC

Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstflxdec.c in the FLIC decoder in GStreamer before 1.10.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via the start_line parameter.

CVE-2016-9813 gstreamer vulnerability CVSS: 4.3 13 Jan 2017, 16:59 UTC

The _parse_pat function in the mpegts parser in GStreamer before 1.10.2 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted file.

CVE-2016-9812 gstreamer vulnerability CVSS: 5.0 13 Jan 2017, 16:59 UTC

The gst_mpegts_section_new function in the mpegts decoder in GStreamer before 1.10.2 allows remote attackers to cause a denial of service (out-of-bounds read) via a too small section.

CVE-2016-9811 gstreamer vulnerability CVSS: 4.3 13 Jan 2017, 16:59 UTC

The windows_icon_typefind function in gst-plugins-base in GStreamer before 1.10.2, when G_SLICE is set to always-malloc, allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted ico file.

CVE-2016-9810 gstreamer vulnerability CVSS: 4.3 13 Jan 2017, 16:59 UTC

The gst_decode_chain_free_internal function in the flxdex decoder in gst-plugins-good in GStreamer before 1.10.2 allows remote attackers to cause a denial of service (invalid memory read and crash) via an invalid file, which triggers an incorrect unref call.

CVE-2016-9809 gstreamer vulnerability CVSS: 6.8 13 Jan 2017, 16:59 UTC

Off-by-one error in the gst_h264_parse_set_caps function in GStreamer before 1.10.2 allows remote attackers to have unspecified impact via a crafted file, which triggers an out-of-bounds read.

CVE-2016-9808 gstreamer vulnerability CVSS: 5.0 13 Jan 2017, 16:59 UTC

The FLIC decoder in GStreamer before 1.10.2 allows remote attackers to cause a denial of service (out-of-bounds write and crash) via a crafted series of skip and count pairs.

CVE-2016-9807 gstreamer vulnerability CVSS: 4.3 13 Jan 2017, 16:59 UTC

The flx_decode_chunks function in gst/flx/gstflxdec.c in GStreamer before 1.10.2 allows remote attackers to cause a denial of service (invalid memory read and crash) via a crafted FLIC file.

CVE-2009-1932 gstreamer vulnerability CVSS: 6.8 04 Jun 2009, 20:30 UTC

Multiple integer overflows in the (1) user_info_callback, (2) user_endrow_callback, and (3) gst_pngdec_task functions (ext/libpng/gstpngdec.c) in GStreamer Good Plug-ins (aka gst-plugins-good or gstreamer-plugins-good) 0.10.15 allow remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted PNG file, which triggers a buffer overflow.

CVE-2009-0398 gstreamer vulnerability CVSS: 9.3 03 Feb 2009, 11:30 UTC

Array index error in the gst_qtp_trak_handler function in gst/qtdemux/qtdemux.c in GStreamer Plug-ins (aka gstreamer-plugins) 0.6.0 allows remote attackers to have an unknown impact via a crafted QuickTime media file.

CVE-2009-0397 gstreamer vulnerability CVSS: 9.3 03 Feb 2009, 11:30 UTC

Heap-based buffer overflow in the qtdemux_parse_samples function in gst/qtdemux/qtdemux.c in GStreamer Good Plug-ins (aka gst-plugins-good) 0.10.9 through 0.10.11, and GStreamer Plug-ins (aka gstreamer-plugins) 0.8.5, might allow remote attackers to execute arbitrary code via crafted Time-to-sample (aka stts) atom data in a malformed QuickTime media .mov file.

CVE-2009-0387 gstreamer vulnerability CVSS: 9.3 02 Feb 2009, 19:30 UTC

Array index error in the qtdemux_parse_samples function in gst/qtdemux/qtdemux.c in GStreamer Good Plug-ins (aka gst-plugins-good) 0.10.9 through 0.10.11 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted Sync Sample (aka stss) atom data in a malformed QuickTime media .mov file, related to "mark keyframes."

CVE-2009-0386 gstreamer vulnerability CVSS: 9.3 02 Feb 2009, 19:30 UTC

Heap-based buffer overflow in the qtdemux_parse_samples function in gst/qtdemux/qtdemux.c in GStreamer Good Plug-ins (aka gst-plugins-good) 0.10.9 through 0.10.11 might allow remote attackers to execute arbitrary code via crafted Composition Time To Sample (ctts) atom data in a malformed QuickTime media .mov file.