Search CVE reports


Toggle filters

1 – 10 of 25 results


CVE-2026-41470

Medium priority
Needs evaluation

LIVE555 before 2026.04.22 contains an authorization bypass vulnerability in RTSP session command handling that allows attackers to replay valid Session tokens from unauthenticated connections. Attackers who obtain a valid Session...

1 affected package

liblivemedia

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
liblivemedia Not in release Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-1200

Medium priority
Needs evaluation

A flaw was found in the rgaufman/live555 fork of live555. A remote attacker could exploit a segmentation fault, in the `increaseBufferTo` function. This vulnerability can lead to memory corruption problems and potentially other...

1 affected package

liblivemedia

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
liblivemedia Not in release Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2025-65407

Medium priority
Needs evaluation

A use-after-free in the MPEG1or2Demux::newElementaryStream() function of Live555 Streaming Media v2018.09.02 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MPEG Program stream.

1 affected package

liblivemedia

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
liblivemedia Not in release Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2025-65408

Medium priority
Needs evaluation

A NULL pointer dereference in the ADTSAudioFileServerMediaSubsession::createNewRTPSink() function of Live555 Streaming Media v2018.09.02 allows attackers to cause a Denial of Service (DoS) via supplying a crafted ADTS file.

1 affected package

liblivemedia

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
liblivemedia Not in release Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2025-65406

Medium priority
Needs evaluation

A heap overflow in the MatroskaFile::createRTPSinkForTrackNumber() function of Live555 Streaming Media v2018.09.02 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MKV file.

1 affected package

liblivemedia

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
liblivemedia Not in release Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2025-65405

Medium priority
Needs evaluation

A use-after-free in the ADTSAudioFileSource::samplingFrequency() function of Live555 Streaming Media v2018.09.02 allows attackers to cause a Denial of Service (DoS) via supplying a crafted ADTS/AAC file.

1 affected package

liblivemedia

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
liblivemedia Not in release Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2025-65404

Medium priority
Needs evaluation

A buffer overflow in the getSideInfo2() function of Live555 Streaming Media v2018.09.02 allows attackers to cause a Denial of Service (DoS) via a crafted MP3 stream.

1 affected package

liblivemedia

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
liblivemedia Not in release Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2023-37117

Medium priority
Needs evaluation

A heap-use-after-free vulnerability was found in live555 version 2023.05.10 while handling the SETUP.

1 affected package

liblivemedia

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
liblivemedia Not in release Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2021-41396

Medium priority
Needs evaluation

Live555 through 1.08 does not handle socket connections properly. A huge number of incoming socket connections in a short time invokes the error-handling module, in which a heap-based buffer overflow happens. An attacker can...

1 affected package

liblivemedia

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
liblivemedia Not in release Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2021-39283

Medium priority
Needs evaluation

liveMedia/FramedSource.cpp in Live555 through 1.08 allows an assertion failure and application exit via multiple SETUP and PLAY commands.

1 affected package

liblivemedia

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
liblivemedia Not in release Not in release Not in release Needs evaluation Needs evaluation
Show less packages