Live555 Streaming Media vulnerabilities

13 known vulnerabilities affecting live555/streaming_media.

Total CVEs
13
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH5MEDIUM5

Vulnerabilities

Page 1 of 1
CVE-2025-65406MEDIUMCVSS 6.5v2018-09-022025-12-01
CVE-2025-65406 [MEDIUM] CWE-122 CVE-2025-65406: A heap overflow in the MatroskaFile::createRTPSinkForTrackNumber() function of Live555 Streaming Med A heap overflow in the MatroskaFile::createRTPSinkForTrackNumber() function of Live555 Streaming Media v2018.09.02 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MKV file.
nvd
CVE-2025-65405MEDIUMCVSS 6.5v2018-09-022025-12-01
CVE-2025-65405 [MEDIUM] CWE-416 CVE-2025-65405: A use-after-free in the ADTSAudioFileSource::samplingFrequency() function of Live555 Streaming Media A use-after-free in the ADTSAudioFileSource::samplingFrequency() function of Live555 Streaming Media v2018.09.02 allows attackers to cause a Denial of Service (DoS) via supplying a crafted ADTS/AAC file.
nvd
CVE-2025-65407MEDIUMCVSS 6.5v2018-09-022025-12-01
CVE-2025-65407 [MEDIUM] CWE-416 CVE-2025-65407: A use-after-free in the MPEG1or2Demux::newElementaryStream() function of Live555 Streaming Media v20 A use-after-free in the MPEG1or2Demux::newElementaryStream() function of Live555 Streaming Media v2018.09.02 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MPEG Program stream.
nvd
CVE-2025-65408MEDIUMCVSS 6.5v2018-09-022025-12-01
CVE-2025-65408 [MEDIUM] CWE-476 CVE-2025-65408: A NULL pointer dereference in the ADTSAudioFileServerMediaSubsession::createNewRTPSink() function of A NULL pointer dereference in the ADTSAudioFileServerMediaSubsession::createNewRTPSink() function of Live555 Streaming Media v2018.09.02 allows attackers to cause a Denial of Service (DoS) via supplying a crafted ADTS file.
nvd
CVE-2025-65404MEDIUMCVSS 6.5v2018-09-022025-12-01
CVE-2025-65404 [MEDIUM] CWE-120 CVE-2025-65404: A buffer overflow in the getSideInfo2() function of Live555 Streaming Media v2018.09.02 allows attac A buffer overflow in the getSideInfo2() function of Live555 Streaming Media v2018.09.02 allows attackers to cause a Denial of Service (DoS) via a crafted MP3 stream.
nvd
CVE-2021-28899HIGHCVSS 7.5fixed in 2021.3.162021-04-29
CVE-2021-28899 [HIGH] CVE-2021-28899: Vulnerability in the AC3AudioFileServerMediaSubsession, ADTSAudioFileServerMediaSubsession, and AMRA Vulnerability in the AC3AudioFileServerMediaSubsession, ADTSAudioFileServerMediaSubsession, and AMRAudioFileServerMediaSubsessionLive OnDemandServerMediaSubsession subclasses in Networks LIVE555 Streaming Media before 2021.3.16.
nvd
CVE-2019-15232CRITICALCVSS 9.8fixed in 2019-08-162019-08-20
CVE-2019-15232 [CRITICAL] CWE-416 CVE-2019-15232: Live555 before 2019.08.16 has a Use-After-Free because GenericMediaServer::createNewClientSessionWit Live555 before 2019.08.16 has a Use-After-Free because GenericMediaServer::createNewClientSessionWithId can generate the same client session ID in succession, which is mishandled by the MPEG1or2 and Matroska file demultiplexors.
nvd
CVE-2019-9215CRITICALCVSS 9.8fixed in 2019.02.272019-02-28
CVE-2019-9215 [CRITICAL] CVE-2019-9215: In Live555 before 2019.02.27, malformed headers lead to invalid memory access in the parseAuthorizat In Live555 before 2019.02.27, malformed headers lead to invalid memory access in the parseAuthorizationHeader function.
nvd
CVE-2019-7732HIGHCVSS 7.5v0.952019-02-11
CVE-2019-7732 [HIGH] CWE-401 CVE-2019-7732: In Live555 0.95, a setup packet can cause a memory leak leading to DoS because, when there are multi In Live555 0.95, a setup packet can cause a memory leak leading to DoS because, when there are multiple instances of a single field (username, realm, nonce, uri, or response), only the last instance can ever be freed.
nvd
CVE-2019-7733HIGHCVSS 7.5v0.952019-02-11
CVE-2019-7733 [HIGH] CWE-190 CVE-2019-7733: In Live555 0.95, there is a buffer overflow via a large integer in a Content-Length HTTP header beca In Live555 0.95, there is a buffer overflow via a large integer in a Content-Length HTTP header because handleRequestBytes has an unrestricted memmove.
nvd
CVE-2019-7314CRITICALCVSS 9.8fixed in 0.952019-02-04
CVE-2019-7314 [CRITICAL] CWE-416 CVE-2019-7314: liblivemedia in Live555 before 2019.02.03 mishandles the termination of an RTSP stream after RTP/RTC liblivemedia in Live555 before 2019.02.03 mishandles the termination of an RTSP stream after RTP/RTCP-over-RTSP has been set up, which could lead to a Use-After-Free error that causes the RTSP server to crash (Segmentation fault) or possibly have unspecified other impact.
nvd
CVE-2013-6933HIGHCVSS 7.5v2011-08-13v2011-08-20+146 more2014-01-23
CVE-2013-6933 [HIGH] CWE-119 CVE-2013-6933: The parseRTSPRequestString function in Live Networks Live555 Streaming Media 2011.08.13 through 2013 The parseRTSPRequestString function in Live Networks Live555 Streaming Media 2011.08.13 through 2013.11.25, as used in VideoLAN VLC Media Player, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a (1) space or (2) tab character at the beginning of an RTSP message, which triggers an integer underflow, i
nvd
CVE-2013-6934HIGHCVSS 7.5v2013-11-262014-01-23
CVE-2013-6934 [HIGH] CVE-2013-6934: The parseRTSPRequestString function in Live Networks Live555 Streaming Media 2013.11.26, as used in The parseRTSPRequestString function in Live Networks Live555 Streaming Media 2013.11.26, as used in VideoLAN VLC Media Player, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a space character at the beginning of an RTSP message, which triggers an integer underflow, infinite loop, and buffer overflow. NOTE: th
nvd