6.8

CVSS4.0

CVE-2024-47542 - GHSL-2024-235: GStreamer ID3v2 parser out-of-bounds read and NULL-pointer dereference

GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference has been discovered in the id3v2_read_synch_uint function, located in id3v2.c. If id3v2_read_synch_uint is called with a null work->hdr.frame_data, the pointer guint8 *data is accessed without va…

πŸ“… Published: Dec. 11, 2024, 6:55 p.m. πŸ”„ Last Modified: March 17, 2026, 3:52 p.m.

6.9

CVSS4.0

CVE-2024-47541 - GHSL-2024-228: GStreamer has an out-of-bounds write in SSA subtitle parser

GStreamer is a library for constructing graphs of media-handling components. An OOB-write vulnerability has been identified in the gst_ssa_parse_remove_override_codes function of the gstssaparse.c file. This function is responsible for parsing and removing SSA (SubStation Alpha) style override code…

πŸ“… Published: Dec. 11, 2024, 6:54 p.m. πŸ”„ Last Modified: March 17, 2026, 3:52 p.m.

8.6

CVSS4.0

CVE-2024-47540 - GHSL-2024-197: GStreamer uses uninitialized stack memory in Matroska/WebM demuxer

GStreamer is a library for constructing graphs of media-handling components. An uninitialized stack variable vulnerability has been identified in the gst_matroska_demux_add_wvpk_header function within matroska-demux.c. When size < 4, the program calls gst_buffer_unmap with an uninitialized map vari…

πŸ“… Published: Dec. 11, 2024, 6:54 p.m. πŸ”„ Last Modified: March 17, 2026, 3:52 p.m.

8.6

CVSS4.0

CVE-2024-47539 - GHSL-2024-195: GStreamer has an OOB-write in convert_to_s334_1a

GStreamer is a library for constructing graphs of media-handling components. An out-of-bounds write vulnerability was identified in the convert_to_s334_1a function in isomp4/qtdemux.c. The vulnerability arises due to a discrepancy between the size of memory allocated to the storage array and the lo…

πŸ“… Published: Dec. 11, 2024, 6:53 p.m. πŸ”„ Last Modified: March 17, 2026, 3:52 p.m.

8.6

CVSS4.0

CVE-2024-47538 - GHSL-2024-115: GStreamer has a stack-buffer overflow in vorbis_handle_identification_packet

GStreamer is a library for constructing graphs of media-handling components. A stack-buffer overflow has been detected in the `vorbis_handle_identification_packet` function within `gstvorbisdec.c`. The position array is a stack-allocated buffer of size 64. If vd->vi.channels exceeds 64, the for loo…

πŸ“… Published: Dec. 11, 2024, 6:52 p.m. πŸ”„ Last Modified: March 17, 2026, 3:52 p.m.

7.5

CVSS3.0

CVE-2024-37401 -

An out-of-bounds read in IPsec of Ivanti Connect Secure before version 22.7R2.1 allows a remote unauthenticated attacker to cause a denial of service.

πŸ“… Published: Dec. 11, 2024, 6:52 p.m. πŸ”„ Last Modified: July 2, 2025, 8:07 p.m.

9.9

CVSS3.0

CVE-2024-42448 -

From the VSPC management agent machine, under condition that the management agent is authorized on the server, it is possible to perform Remote Code Execution (RCE) on the VSPC server machine.

πŸ“… Published: Dec. 11, 2024, 6:52 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.0

CVE-2024-37377 -

A heap-based buffer overflow in IPsec of Ivanti Connect Secure before version 22.7R2.3 allows a remote unauthenticated attacker to cause a denial of service.

πŸ“… Published: Dec. 11, 2024, 6:52 p.m. πŸ”„ Last Modified: July 2, 2025, 8:26 p.m.

8.6

CVSS4.0

CVE-2024-47537 - GHSL-2024-094: GStreamer has an OOB-write in isomp4/qtdemux.c

GStreamer is a library for constructing graphs of media-handling components. The program attempts to reallocate the memory pointed to by stream->samples to accommodate stream->n_samples + samples_count elements of type QtDemuxSample. The problem is that samples_count is read from the input file. An…

πŸ“… Published: Dec. 11, 2024, 6:51 p.m. πŸ”„ Last Modified: March 17, 2026, 3:52 p.m.

5.3

CVSS4.0

CVE-2024-12479 - cjbi wetech-cms TopicDao.java searchTopicByKeyword sql injection

A vulnerability was found in cjbi wetech-cms 1.0/1.1/1.2 and classified as critical. This issue affects the function searchTopicByKeyword of the file wetech-cms-master\wetech-core\src\main\java\tech\wetech\cms\dao\TopicDao.java. The manipulation of the argument keyword leads to sql injection. The a…

πŸ“… Published: Dec. 11, 2024, 6:31 p.m. πŸ”„ Last Modified: Dec. 13, 2024, 5:10 p.m.
Total resulsts: 349182
Page 7522 of 34,919
Β« previous page Β» next page
Filters