299,584
Total vulnerabilities in the database
The vmnc decoder in the gstreamer does not initialize the render canvas, which allows remote attackers to obtain sensitive information as demonstrated by thumbnailing a simple 1 frame vmnc movie that does not draw to the allocated render canvas.
| Software | From | Fixed in |
|---|---|---|
| gstreamer_project / gstreamer | - | 1.11.1 |
| redhat / enterprise_linux_desktop | 7.0 | 7.0.x |
| redhat / enterprise_linux_workstation | 7.0 | 7.0.x |
| redhat / enterprise_linux_server | 7.0 | 7.0.x |
| redhat / enterprise_linux_server_aus | 7.4 | 7.4.x |
| redhat / enterprise_linux_eus | 7.4 | 7.4.x |
| redhat / enterprise_linux_eus | 7.5 | 7.5.x |
| redhat / enterprise_linux_server_tus | 7.6 | 7.6.x |
| redhat / enterprise_linux_server_aus | 7.6 | 7.6.x |
| redhat / enterprise_linux_eus | 7.6 | 7.6.x |
| redhat / enterprise_linux_server_aus | 7.7 | 7.7.x |
| redhat / enterprise_linux_server_tus | 7.7 | 7.7.x |
| redhat / enterprise_linux_eus | 7.7 | 7.7.x |
| fedoraproject / fedora | 35 | 35.x |