Show filters
22 Total Results
Displaying 11-20 of 22
Sort by:
Attacker Value
Unknown

CVE-2019-7733

Disclosure Date: February 11, 2019 (last updated November 27, 2024)
In Live555 0.95, there is a buffer overflow via a large integer in a Content-Length HTTP header because handleRequestBytes has an unrestricted memmove.
0
Attacker Value
Unknown

CVE-2019-7732

Disclosure Date: February 11, 2019 (last updated November 27, 2024)
In Live555 0.95, a setup packet can cause a memory leak leading to DoS because, when there are multiple instances of a single field (username, realm, nonce, uri, or response), only the last instance can ever be freed.
0
Attacker Value
Unknown

CVE-2019-7314

Disclosure Date: February 04, 2019 (last updated November 27, 2024)
liblivemedia in Live555 before 2019.02.03 mishandles the termination of an RTSP stream after RTP/RTCP-over-RTSP has been set up, which could lead to a Use-After-Free error that causes the RTSP server to crash (Segmentation fault) or possibly have unspecified other impact.
0
Attacker Value
Unknown

CVE-2017-7638

Disclosure Date: March 08, 2018 (last updated November 26, 2024)
QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier does not authenticate requests properly. Successful exploitation could lead to change of the Media Streaming settings, and leakage of sensitive information of the QNAP NAS.
0
Attacker Value
Unknown

CVE-2017-7640

Disclosure Date: March 08, 2018 (last updated November 26, 2024)
QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier allows remote attackers to run arbitrary OS commands against the system with root privileges.
0
Attacker Value
Unknown

CVE-2017-7634

Disclosure Date: March 08, 2018 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier allows remote attackers to inject arbitrary web script or HTML. The injected code will only be triggered by a crafted link, not the normal page.
0
Attacker Value
Unknown

CVE-2017-7641

Disclosure Date: March 08, 2018 (last updated November 26, 2024)
QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier does not utilize CSRF protections.
0
Attacker Value
Unknown

CVE-2017-9805

Disclosure Date: September 15, 2017 (last updated July 26, 2024)
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code Execution when deserializing XML payloads.
Attacker Value
Unknown

CVE-2013-6933

Disclosure Date: January 23, 2014 (last updated October 05, 2023)
The parseRTSPRequestString function in Live Networks Live555 Streaming Media 2011.08.13 through 2013.11.25, as used in VideoLAN VLC Media Player, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a (1) space or (2) tab character at the beginning of an RTSP message, which triggers an integer underflow, infinite loop, and buffer overflow.
0
Attacker Value
Unknown

CVE-2013-6934

Disclosure Date: January 23, 2014 (last updated October 05, 2023)
The parseRTSPRequestString function in Live Networks Live555 Streaming Media 2013.11.26, as used in VideoLAN VLC Media Player, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a space character at the beginning of an RTSP message, which triggers an integer underflow, infinite loop, and buffer overflow. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-6933.
0