live555 CVE Vulnerabilities & Metrics

Focus on live555 vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About live555 Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with live555. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total live555 CVEs: 13
Earliest CVE date: 23 Jan 2014, 21:55 UTC
Latest CVE date: 12 Jan 2024, 07:15 UTC

Latest CVE reference: CVE-2023-37117

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -100.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -100.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical live555 CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 5.91

Max CVSS: 7.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 1
4.0-6.9 6
7.0-8.9 8
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS live555 CVEs

These are the five CVEs with the highest CVSS scores for live555, sorted by severity first and recency.

All CVEs for live555

CVE-2023-37117 live555 vulnerability CVSS: 0 12 Jan 2024, 07:15 UTC

A heap-use-after-free vulnerability was found in live555 version 2023.05.10 while handling the SETUP.

CVE-2021-38382 live555 vulnerability CVSS: 4.3 10 Aug 2021, 18:15 UTC

Live555 through 1.08 does not handle Matroska and Ogg files properly. Sending two successive RTSP SETUP commands for the same track causes a Use-After-Free and daemon crash.

CVE-2021-38381 live555 vulnerability CVSS: 4.3 10 Aug 2021, 18:15 UTC

Live555 through 1.08 does not handle MPEG-1 or 2 files properly. Sending two successive RTSP SETUP commands for the same track causes a Use-After-Free and daemon crash.

CVE-2021-38380 live555 vulnerability CVSS: 5.0 10 Aug 2021, 18:15 UTC

Live555 through 1.08 mishandles huge requests for the same MP3 stream, leading to recursion and s stack-based buffer over-read. An attacker can leverage this to launch a DoS attack.

CVE-2021-28899 live555 vulnerability CVSS: 5.0 29 Apr 2021, 15:15 UTC

Vulnerability in the AC3AudioFileServerMediaSubsession, ADTSAudioFileServerMediaSubsession, and AMRAudioFileServerMediaSubsessionLive OnDemandServerMediaSubsession subclasses in Networks LIVE555 Streaming Media before 2021.3.16.

CVE-2020-24027 live555 vulnerability CVSS: 7.5 11 Jan 2021, 20:15 UTC

In Live Networks, Inc., liblivemedia version 20200625, there is a potential buffer overflow bug in the server handling of a RTSP "PLAY" command, when the command specifies seeking by absolute time.

CVE-2019-15232 live555 vulnerability CVSS: 7.5 20 Aug 2019, 00:15 UTC

Live555 before 2019.08.16 has a Use-After-Free because GenericMediaServer::createNewClientSessionWithId can generate the same client session ID in succession, which is mishandled by the MPEG1or2 and Matroska file demultiplexors.

CVE-2019-9215 live555 vulnerability CVSS: 7.5 28 Feb 2019, 04:29 UTC

In Live555 before 2019.02.27, malformed headers lead to invalid memory access in the parseAuthorizationHeader function.

CVE-2019-7733 live555 vulnerability CVSS: 5.0 11 Feb 2019, 17:29 UTC

In Live555 0.95, there is a buffer overflow via a large integer in a Content-Length HTTP header because handleRequestBytes has an unrestricted memmove.

CVE-2019-7732 live555 vulnerability CVSS: 5.0 11 Feb 2019, 17:29 UTC

In Live555 0.95, a setup packet can cause a memory leak leading to DoS because, when there are multiple instances of a single field (username, realm, nonce, uri, or response), only the last instance can ever be freed.

CVE-2019-7314 live555 vulnerability CVSS: 7.5 04 Feb 2019, 02:29 UTC

liblivemedia in Live555 before 2019.02.03 mishandles the termination of an RTSP stream after RTP/RTCP-over-RTSP has been set up, which could lead to a Use-After-Free error that causes the RTSP server to crash (Segmentation fault) or possibly have unspecified other impact.

CVE-2019-6256 live555 vulnerability CVSS: 7.5 14 Jan 2019, 08:29 UTC

A Denial of Service issue was discovered in the LIVE555 Streaming Media libraries as used in Live555 Media Server 0.93. It can cause an RTSPServer crash in handleHTTPCmd_TunnelingPOST, when RTSP-over-HTTP tunneling is supported, via x-sessioncookie HTTP headers in a GET request and a POST request within the same TCP session. This occurs because of a call to an incorrect virtual function pointer in the readSocket function in GroupsockHelper.cpp.

CVE-2018-4013 live555 vulnerability CVSS: 7.5 19 Oct 2018, 13:29 UTC

An exploitable code execution vulnerability exists in the HTTP packet-parsing functionality of the LIVE555 RTSP server library version 0.92. A specially crafted packet can cause a stack-based buffer overflow, resulting in code execution. An attacker can send a packet to trigger this vulnerability.

CVE-2013-6934 live555 vulnerability CVSS: 7.5 23 Jan 2014, 21:55 UTC

The parseRTSPRequestString function in Live Networks Live555 Streaming Media 2013.11.26, as used in VideoLAN VLC Media Player, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a space character at the beginning of an RTSP message, which triggers an integer underflow, infinite loop, and buffer overflow. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-6933.

CVE-2013-6933 live555 vulnerability CVSS: 7.5 23 Jan 2014, 21:55 UTC

The parseRTSPRequestString function in Live Networks Live555 Streaming Media 2011.08.13 through 2013.11.25, as used in VideoLAN VLC Media Player, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a (1) space or (2) tab character at the beginning of an RTSP message, which triggers an integer underflow, infinite loop, and buffer overflow.