Записи live555
24 опубликованных записей вендора live555.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 29,2 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-416 Use After Free7
- CWE-787 Out-of-bounds Write3
- CWE-401 Missing Release of Memory after Effective Lifetime2
- CWE-125 Out-of-bounds Read1
- CWE-189 Numeric Errors1
- CWE-190 Integer Overflow or Wraparound1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
24 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
42В плане | CVE-2018-4013Proof of concept | An exploitable code execution vulnerability exists in the HTTP packet-parsing functionality of the LIVE555 RTSP server library version 0.92.live555 · live555 media server · CWE-787 | Критическая9,8 | — | 9,7 % | 19 окт. 2018 г. |
40В плане | CVE-2019-7314Эксплойта нет | liblivemedia in Live555 before 2019.02.03 mishandles the termination of an RTSP stream after RTP/RTCP-over-RTSP has been set up, which couldlive555 · streaming media · CWE-416 | Критическая9,8 | — | 3,2 % | 3 февр. 2019 г. |
40В плане | CVE-2019-6256Эксплойта нет | A Denial of Service issue was discovered in the LIVE555 Streaming Media libraries as used in Live555 Media Server 0.93.live555 · live555 media server · CWE-755 | Критическая9,8 | — | 2,4 % | 14 янв. 2019 г. |
40В плане | CVE-2019-9215Эксплойта нет | In Live555 before 2019.02.27, malformed headers lead to invalid memory access in the parseAuthorizationHeader function.live555 · streaming media | Критическая9,8 | — | 2,2 % | 28 февр. 2019 г. |
40В плане | CVE-2019-15232Эксплойта нет | Live555 before 2019.08.16 has a Use-After-Free because GenericMediaServer::createNewClientSessionWithId can generate the same client sessionlive555 · streaming media · CWE-416 | Критическая9,8 | — | 1,7 % | 19 авг. 2019 г. |
39Наблюдать | CVE-2020-24027Эксплойта нет | In Live Networks, Inc., liblivemedia version 20200625, there is a potential buffer overflow bug in the server handling of a RTSP "PLAY" commlive555 · liblivemedia · CWE-787 | Критическая9,8 | — | 1,6 % | 11 янв. 2021 г. |
39Наблюдать | CVE-2023-37117Эксплойта нет | A heap-use-after-free vulnerability was found in live555 version 2023.05.10 while handling the SETUP.live555 · live555 · CWE-416 | Критическая9,8 | — | 0,9 % | 12 янв. 2024 г. |
38Наблюдать | CVE-2013-6934Эксплойта нет | The parseRTSPRequestString function in Live Networks Live555 Streaming Media 2013.11.26, as used in VideoLAN VLC Media Player, allows remotelive555 · streaming media · CWE-189 | Высокая7,5 | — | 28,2 % | 23 янв. 2014 г. |
35Наблюдать | CVE-2013-6933Эксплойта нет | The parseRTSPRequestString function in Live Networks Live555 Streaming Media 2011.08.13 through 2013.11.25, as used in VideoLAN VLC Media Pllive555 · streaming media · CWE-119 | Высокая7,5 | — | 17,4 % | 23 янв. 2014 г. |
30Наблюдать | CVE-2019-7733Эксплойта нет | In Live555 0.95, there is a buffer overflow via a large integer in a Content-Length HTTP header because handleRequestBytes has an unrestrictlive555 · streaming media · CWE-190 | Высокая7,5 | — | 1,6 % | 11 февр. 2019 г. |
30Наблюдать | CVE-2021-39282Эксплойта нет | Live555 through 1.08 has a memory leak in AC3AudioStreamParser for AC3 files.live555 · live555 · CWE-401 | Высокая7,5 | — | 1,5 % | 18 авг. 2021 г. |
30Наблюдать | CVE-2021-38380Эксплойта нет | Live555 through 1.08 mishandles huge requests for the same MP3 stream, leading to recursion and s stack-based buffer over-read.live555 · live555 · CWE-125 | Высокая7,5 | — | 1,5 % | 10 авг. 2021 г. |
30Наблюдать | CVE-2019-7732Эксплойта нет | In Live555 0.95, a setup packet can cause a memory leak leading to DoS because, when there are multiple instances of a single field (usernamlive555 · streaming media · CWE-401 | Высокая7,5 | — | 1,4 % | 11 февр. 2019 г. |
30Наблюдать | CVE-2021-41396Эксплойта нет | Live555 through 1.08 does not handle socket connections properly.live555 · live555 · CWE-787 | Высокая7,5 | — | 1,4 % | 12 июл. 2022 г. |
30Наблюдать | CVE-2021-28899Эксплойта нет | Vulnerability in the AC3AudioFileServerMediaSubsession, ADTSAudioFileServerMediaSubsession, and AMRAudioFileServerMediaSubsessionLive OnDemalive555 · streaming media | Высокая7,5 | — | 1,1 % | 29 апр. 2021 г. |
29Наблюдать | CVE-2007-6036Proof of concept | The parseRTSPRequestString function in LIVE555 Media Server 2007.11.01 and earlier allows remote attackers to cause a denial of service (daelive555 · media server · CWE-20 | Высокая7,1 | — | 4,4 % | 20 нояб. 2007 г. |
26Наблюдать | CVE-2021-38382Эксплойта нет | Live555 through 1.08 does not handle Matroska and Ogg files properly.live555 · live555 · CWE-416 | Средняя6,5 | — | 1,2 % | 10 авг. 2021 г. |
26Наблюдать | CVE-2021-38381Эксплойта нет | Live555 through 1.08 does not handle MPEG-1 or 2 files properly.live555 · live555 · CWE-416 | Средняя6,5 | — | 1,2 % | 10 авг. 2021 г. |
26Наблюдать | CVE-2025-65406Эксплойта нет | A heap overflow in the MatroskaFile::createRTPSinkForTrackNumber() function of Live555 Streaming Media v2018.09.02 allows attackers to causelive555 · streaming media · CWE-122 | Средняя6,5 | — | 0,3 % | 1 дек. 2025 г. |
26Наблюдать | CVE-2025-65404Эксплойта нет | A buffer overflow in the getSideInfo2() function of Live555 Streaming Media v2018.09.02 allows attackers to cause a Denial of Service (DoS) live555 · streaming media · CWE-120 | Средняя6,5 | — | 0,3 % | 1 дек. 2025 г. |
26Наблюдать | CVE-2025-65408Эксплойта нет | A NULL pointer dereference in the ADTSAudioFileServerMediaSubsession::createNewRTPSink() function of Live555 Streaming Media v2018.09.02 alllive555 · streaming media · CWE-476 | Средняя6,5 | — | 0,3 % | 1 дек. 2025 г. |
26Наблюдать | CVE-2025-65405Эксплойта нет | A use-after-free in the ADTSAudioFileSource::samplingFrequency() function of Live555 Streaming Media v2018.09.02 allows attackers to cause alive555 · streaming media · CWE-416 | Средняя6,5 | — | 0,3 % | 1 дек. 2025 г. |
26Наблюдать | CVE-2025-65407Эксплойта нет | A use-after-free in the MPEG1or2Demux::newElementaryStream() function of Live555 Streaming Media v2018.09.02 allows attackers to cause a Denlive555 · streaming media · CWE-416 | Средняя6,5 | — | 0,3 % | 1 дек. 2025 г. |
22Наблюдать | CVE-2021-39283Эксплойта нет | liveMedia/FramedSource.cpp in Live555 through 1.08 allows an assertion failure and application exit via multiple SETUP and PLAY commands.live555 · live555 · CWE-617 | Средняя5,5 | — | 0,9 % | 18 авг. 2021 г. |
- CVE-2018-401342В плане
An exploitable code execution vulnerability exists in the HTTP packet-parsing functionality of the LIVE555 RTSP server library version 0.92.
КритическаяCVSS 9,8Proof of conceptEPSS 10 %live555 · live555 media server19 окт. 2018 г.
- CVE-2019-731440В плане
liblivemedia in Live555 before 2019.02.03 mishandles the termination of an RTSP stream after RTP/RTCP-over-RTSP has been set up, which could
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %live555 · streaming media3 февр. 2019 г.
- CVE-2019-625640В плане
A Denial of Service issue was discovered in the LIVE555 Streaming Media libraries as used in Live555 Media Server 0.93.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %live555 · live555 media server14 янв. 2019 г.
- CVE-2019-921540В плане
In Live555 before 2019.02.27, malformed headers lead to invalid memory access in the parseAuthorizationHeader function.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %live555 · streaming media28 февр. 2019 г.
- CVE-2019-1523240В плане
Live555 before 2019.08.16 has a Use-After-Free because GenericMediaServer::createNewClientSessionWithId can generate the same client session
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %live555 · streaming media19 авг. 2019 г.
- CVE-2020-2402739Наблюдать
In Live Networks, Inc., liblivemedia version 20200625, there is a potential buffer overflow bug in the server handling of a RTSP "PLAY" comm
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %live555 · liblivemedia11 янв. 2021 г.
- CVE-2023-3711739Наблюдать
A heap-use-after-free vulnerability was found in live555 version 2023.05.10 while handling the SETUP.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %live555 · live55512 янв. 2024 г.
- CVE-2013-693438Наблюдать
The parseRTSPRequestString function in Live Networks Live555 Streaming Media 2013.11.26, as used in VideoLAN VLC Media Player, allows remote
ВысокаяCVSS 7,5Эксплойта нетEPSS 28 %live555 · streaming media23 янв. 2014 г.
- CVE-2013-693335Наблюдать
The parseRTSPRequestString function in Live Networks Live555 Streaming Media 2011.08.13 through 2013.11.25, as used in VideoLAN VLC Media Pl
ВысокаяCVSS 7,5Эксплойта нетEPSS 17 %live555 · streaming media23 янв. 2014 г.
- CVE-2019-773330Наблюдать
In Live555 0.95, there is a buffer overflow via a large integer in a Content-Length HTTP header because handleRequestBytes has an unrestrict
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %live555 · streaming media11 февр. 2019 г.
- CVE-2021-3928230Наблюдать
Live555 through 1.08 has a memory leak in AC3AudioStreamParser for AC3 files.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %live555 · live55518 авг. 2021 г.
- CVE-2021-3838030Наблюдать
Live555 through 1.08 mishandles huge requests for the same MP3 stream, leading to recursion and s stack-based buffer over-read.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %live555 · live55510 авг. 2021 г.
- CVE-2019-773230Наблюдать
In Live555 0.95, a setup packet can cause a memory leak leading to DoS because, when there are multiple instances of a single field (usernam
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %live555 · streaming media11 февр. 2019 г.
- CVE-2021-4139630Наблюдать
Live555 through 1.08 does not handle socket connections properly.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %live555 · live55512 июл. 2022 г.
- CVE-2021-2889930Наблюдать
Vulnerability in the AC3AudioFileServerMediaSubsession, ADTSAudioFileServerMediaSubsession, and AMRAudioFileServerMediaSubsessionLive OnDema
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %live555 · streaming media29 апр. 2021 г.
- CVE-2007-603629Наблюдать
The parseRTSPRequestString function in LIVE555 Media Server 2007.11.01 and earlier allows remote attackers to cause a denial of service (dae
ВысокаяCVSS 7,1Proof of conceptEPSS 4 %live555 · media server20 нояб. 2007 г.
- CVE-2021-3838226Наблюдать
Live555 through 1.08 does not handle Matroska and Ogg files properly.
СредняяCVSS 6,5Эксплойта нетEPSS 1 %live555 · live55510 авг. 2021 г.
- CVE-2021-3838126Наблюдать
Live555 through 1.08 does not handle MPEG-1 or 2 files properly.
СредняяCVSS 6,5Эксплойта нетEPSS 1 %live555 · live55510 авг. 2021 г.
- CVE-2025-6540626Наблюдать
A heap overflow in the MatroskaFile::createRTPSinkForTrackNumber() function of Live555 Streaming Media v2018.09.02 allows attackers to cause
СредняяCVSS 6,5Эксплойта нетEPSS 0 %live555 · streaming media1 дек. 2025 г.
- CVE-2025-6540426Наблюдать
A buffer overflow in the getSideInfo2() function of Live555 Streaming Media v2018.09.02 allows attackers to cause a Denial of Service (DoS)
СредняяCVSS 6,5Эксплойта нетEPSS 0 %live555 · streaming media1 дек. 2025 г.
- CVE-2025-6540826Наблюдать
A NULL pointer dereference in the ADTSAudioFileServerMediaSubsession::createNewRTPSink() function of Live555 Streaming Media v2018.09.02 all
СредняяCVSS 6,5Эксплойта нетEPSS 0 %live555 · streaming media1 дек. 2025 г.
- CVE-2025-6540526Наблюдать
A use-after-free in the ADTSAudioFileSource::samplingFrequency() function of Live555 Streaming Media v2018.09.02 allows attackers to cause a
СредняяCVSS 6,5Эксплойта нетEPSS 0 %live555 · streaming media1 дек. 2025 г.
- CVE-2025-6540726Наблюдать
A use-after-free in the MPEG1or2Demux::newElementaryStream() function of Live555 Streaming Media v2018.09.02 allows attackers to cause a Den
СредняяCVSS 6,5Эксплойта нетEPSS 0 %live555 · streaming media1 дек. 2025 г.
- CVE-2021-3928322Наблюдать
liveMedia/FramedSource.cpp in Live555 through 1.08 allows an assertion failure and application exit via multiple SETUP and PLAY commands.
СредняяCVSS 5,5Эксплойта нетEPSS 1 %live555 · live55518 авг. 2021 г.