← Back

Live555

live555

Vendor: Live555 • 7 CVEs

CVEs (7)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Live555
1Live555
Nov 21, 2024
Jan 12, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A heap-use-after-free vulnerability was found in live555 version 2023.05.10 while handling the SETUP.
1Live555
1Live555
Nov 21, 2024
Jul 12, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Live555 through 1.08 does not handle socket connections properly. A huge number of incoming socket connections in a short time invokes the error-handling module, in which a heap-based buffer overflow happens. An attacker...Show more
Live555 through 1.08 does not handle socket connections properly. A huge number of incoming socket connections in a short time invokes the error-handling module, in which a heap-based buffer overflow happens. An attacker can leverage this to launch a DoS attack.Show less
1Live555
1Live555
Nov 21, 2024
Aug 18, 2021
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
liveMedia/FramedSource.cpp in Live555 through 1.08 allows an assertion failure and application exit via multiple SETUP and PLAY commands.
1Live555
1Live555
Nov 21, 2024
Aug 18, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Live555 through 1.08 has a memory leak in AC3AudioStreamParser for AC3 files.
1Live555
1Live555
Nov 21, 2024
Aug 10, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Live555 through 1.08 does not handle Matroska and Ogg files properly. Sending two successive RTSP SETUP commands for the same track causes a Use-After-Free and daemon crash.
1Live555
1Live555
Nov 21, 2024
Aug 10, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Live555 through 1.08 does not handle MPEG-1 or 2 files properly. Sending two successive RTSP SETUP commands for the same track causes a Use-After-Free and daemon crash.
1Live555
1Live555
Nov 21, 2024
Aug 10, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Live555 through 1.08 mishandles huge requests for the same MP3 stream, leading to recursion and s stack-based buffer over-read. An attacker can leverage this to launch a DoS attack.