CVE-2015-0797
GStreamer before 1.4.5, as used in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 on Linux, allows remote attackers to cause a denial of service (buffer over-read and application crash) or possibly execute arbitrary code via crafted H.264 video data in an m4v file.
- Affected products
- Centos, Firefox Esr, Gstreamer, Firefox, Red Hat, Suse, Thunderbird
- Gstreamer
- < 1.4.5
- Mozilla Firefox
- < 38.0, 31.7
- Mozilla Seamonkey
- < 2.35
- Mozilla Thunderbird
- < 31.7, 38.0.1
- CVSS 2.0
- 6.8 MEDIUM
- EPSS
- 5.4% (92th percentile)
- NVD status
- Modified
- Published
- 2015-05-14
CVE-2015-0797 at NVD
1 known exploit for CVE-2015-0797
Proof-of-concept code and exploit modules indexed by Sploitus