Show filters
19 Total Results
Displaying 11-19 of 19
Sort by:
Attacker Value
Unknown

CVE-2019-9215

Disclosure Date: February 28, 2019 (last updated November 27, 2024)
In Live555 before 2019.02.27, malformed headers lead to invalid memory access in the parseAuthorizationHeader function.
Attacker Value
Unknown

CVE-2019-7733

Disclosure Date: February 11, 2019 (last updated November 27, 2024)
In Live555 0.95, there is a buffer overflow via a large integer in a Content-Length HTTP header because handleRequestBytes has an unrestricted memmove.
0
Attacker Value
Unknown

CVE-2019-7732

Disclosure Date: February 11, 2019 (last updated November 27, 2024)
In Live555 0.95, a setup packet can cause a memory leak leading to DoS because, when there are multiple instances of a single field (username, realm, nonce, uri, or response), only the last instance can ever be freed.
0
Attacker Value
Unknown

CVE-2019-7314

Disclosure Date: February 04, 2019 (last updated November 27, 2024)
liblivemedia in Live555 before 2019.02.03 mishandles the termination of an RTSP stream after RTP/RTCP-over-RTSP has been set up, which could lead to a Use-After-Free error that causes the RTSP server to crash (Segmentation fault) or possibly have unspecified other impact.
0
Attacker Value
Unknown

CVE-2019-6256

Disclosure Date: January 14, 2019 (last updated November 27, 2024)
A Denial of Service issue was discovered in the LIVE555 Streaming Media libraries as used in Live555 Media Server 0.93. It can cause an RTSPServer crash in handleHTTPCmd_TunnelingPOST, when RTSP-over-HTTP tunneling is supported, via x-sessioncookie HTTP headers in a GET request and a POST request within the same TCP session. This occurs because of a call to an incorrect virtual function pointer in the readSocket function in GroupsockHelper.cpp.
0
Attacker Value
Unknown

CVE-2018-4013

Disclosure Date: October 19, 2018 (last updated November 27, 2024)
An exploitable code execution vulnerability exists in the HTTP packet-parsing functionality of the LIVE555 RTSP server library version 0.92. A specially crafted packet can cause a stack-based buffer overflow, resulting in code execution. An attacker can send a packet to trigger this vulnerability.
Attacker Value
Unknown

CVE-2013-6933

Disclosure Date: January 23, 2014 (last updated October 05, 2023)
The parseRTSPRequestString function in Live Networks Live555 Streaming Media 2011.08.13 through 2013.11.25, as used in VideoLAN VLC Media Player, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a (1) space or (2) tab character at the beginning of an RTSP message, which triggers an integer underflow, infinite loop, and buffer overflow.
0
Attacker Value
Unknown

CVE-2013-6934

Disclosure Date: January 23, 2014 (last updated October 05, 2023)
The parseRTSPRequestString function in Live Networks Live555 Streaming Media 2013.11.26, as used in VideoLAN VLC Media Player, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a space character at the beginning of an RTSP message, which triggers an integer underflow, infinite loop, and buffer overflow. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-6933.
0
Attacker Value
Unknown

CVE-2007-6036

Disclosure Date: November 20, 2007 (last updated October 04, 2023)
The parseRTSPRequestString function in LIVE555 Media Server 2007.11.01 and earlier allows remote attackers to cause a denial of service (daemon crash) via a short RTSP query, which causes a negative number to be used during memory allocation.
0