DNA View

High Severity Vulnerability

This vulnerability has been rated as High severity. Immediate action is recommended.

CVE-2025-47219

High
Low Medium High Critical
8.1
CVSS Score
Published: Aug 07, 2025
Last Modified: Mar 17, 2026

Vulnerability Description

In GStreamer through 1.26.1, the isomp4 plugin's qtdemux_parse_trak function may read past the end of a heap buffer while parsing an MP4 file, possibly leading to information disclosure.

CVSS Metrics

Common Vulnerability Scoring System

Vector String:

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
N
Attack Complexity
H
Privileges Required
N
User Interaction
N
Scope
U
Confidentiality
H
Integrity
H
Availability
H

Known Affected Software

42 configuration(s) from 1 vendor(s)

gstreamer
Version:
0.10.34
CPE:
cpe:2.3:a:gstreamer:gstreamer:0.10.34:*:*:*:*:*:*:*
gstreamer
Version:
0.10.9
CPE:
cpe:2.3:a:gstreamer:gstreamer:0.10.9:*:*:*:*:*:*:*
gstreamer
Version:
0.10.27
CPE:
cpe:2.3:a:gstreamer:gstreamer:0.10.27:*:*:*:*:*:*:*
gstreamer
Version:
0.10.13
CPE:
cpe:2.3:a:gstreamer:gstreamer:0.10.13:*:*:*:*:*:*:*
gstreamer
Version:
0.10.3
CPE:
cpe:2.3:a:gstreamer:gstreamer:0.10.3:*:*:*:*:*:*:*
gstreamer
Version:
0.10.11
CPE:
cpe:2.3:a:gstreamer:gstreamer:0.10.11:*:*:*:*:*:*:*
gstreamer
Version:
0.10.26
CPE:
cpe:2.3:a:gstreamer:gstreamer:0.10.26:*:*:*:*:*:*:*
gstreamer
Version:
0.10.28
CPE:
cpe:2.3:a:gstreamer:gstreamer:0.10.28:*:*:*:*:*:*:*
gstreamer
Version:
1.10.0
CPE:
cpe:2.3:a:gstreamer:gstreamer:1.10.0:*:*:*:*:*:*:*
gstreamer
Version:
0.10.6
CPE:
cpe:2.3:a:gstreamer:gstreamer:0.10.6:*:*:*:*:*:*:*
gstreamer
Version:
0.10.24
CPE:
cpe:2.3:a:gstreamer:gstreamer:0.10.24:*:*:*:*:*:*:*
gstreamer
Version:
0.10.29
CPE:
cpe:2.3:a:gstreamer:gstreamer:0.10.29:*:*:*:*:*:*:*
gstreamer
Version:
0.10.31
CPE:
cpe:2.3:a:gstreamer:gstreamer:0.10.31:*:*:*:*:*:*:*
gstreamer
Version:
0.10.12
CPE:
cpe:2.3:a:gstreamer:gstreamer:0.10.12:*:*:*:*:*:*:*
gstreamer
Version:
0.10.16
CPE:
cpe:2.3:a:gstreamer:gstreamer:0.10.16:*:*:*:*:*:*:*
gstreamer
Version:
0.10.18
CPE:
cpe:2.3:a:gstreamer:gstreamer:0.10.18:*:*:*:*:*:*:*
gstreamer
Version:
1.24.0
CPE:
cpe:2.3:a:gstreamer:gstreamer:1.24.0:*:*:*:*:*:*:*
gstreamer
Version:
1.24.1
CPE:
cpe:2.3:a:gstreamer:gstreamer:1.24.1:*:*:*:*:*:*:*
gstreamer
Version:
0.10.35
CPE:
cpe:2.3:a:gstreamer:gstreamer:0.10.35:*:*:*:*:*:*:*
gstreamer
Version:
0.10.4
CPE:
cpe:2.3:a:gstreamer:gstreamer:0.10.4:*:*:*:*:*:*:*
gstreamer
Version:
0.10.25
CPE:
cpe:2.3:a:gstreamer:gstreamer:0.10.25:*:*:*:*:*:*:*
gstreamer
Version:
0.10.1
CPE:
cpe:2.3:a:gstreamer:gstreamer:0.10.1:*:*:*:*:*:*:*
gstreamer
Version:
0.10.8
CPE:
cpe:2.3:a:gstreamer:gstreamer:0.10.8:*:*:*:*:*:*:*
gstreamer
Version:
0.10.22
CPE:
cpe:2.3:a:gstreamer:gstreamer:0.10.22:*:*:*:*:*:*:*
gstreamer
Version:
1.22.3
CPE:
cpe:2.3:a:gstreamer:gstreamer:1.22.3:*:*:*:*:*:*:*
gstreamer
Version:
0.10.5
CPE:
cpe:2.3:a:gstreamer:gstreamer:0.10.5:*:*:*:*:*:*:*
gstreamer
Version:
0.10.30
CPE:
cpe:2.3:a:gstreamer:gstreamer:0.10.30:*:*:*:*:*:*:*
gstreamer
Version:
0.10.19
CPE:
cpe:2.3:a:gstreamer:gstreamer:0.10.19:*:*:*:*:*:*:*
gstreamer
Version:
0.10.10
CPE:
cpe:2.3:a:gstreamer:gstreamer:0.10.10:*:*:*:*:*:*:*
gstreamer
Version:
0.10.20
CPE:
cpe:2.3:a:gstreamer:gstreamer:0.10.20:*:*:*:*:*:*:*
gstreamer
Version:
0.10.14
CPE:
cpe:2.3:a:gstreamer:gstreamer:0.10.14:*:*:*:*:*:*:*
gstreamer
Version:
0.10.0
CPE:
cpe:2.3:a:gstreamer:gstreamer:0.10.0:*:*:*:*:*:*:*
gstreamer
Version:
0.10.15
CPE:
cpe:2.3:a:gstreamer:gstreamer:0.10.15:*:*:*:*:*:*:*
gstreamer
Version:
0.10.36
CPE:
cpe:2.3:a:gstreamer:gstreamer:0.10.36:*:*:*:*:*:*:*
gstreamer
Version:
0.10.23
CPE:
cpe:2.3:a:gstreamer:gstreamer:0.10.23:*:*:*:*:*:*:*
gstreamer
Version:
0.10.33
CPE:
cpe:2.3:a:gstreamer:gstreamer:0.10.33:*:*:*:*:*:*:*
gstreamer
Version:
0.10.32
CPE:
cpe:2.3:a:gstreamer:gstreamer:0.10.32:*:*:*:*:*:*:*
gstreamer
Version:
0.10.2
CPE:
cpe:2.3:a:gstreamer:gstreamer:0.10.2:*:*:*:*:*:*:*
gstreamer
Version:
0.10.7
CPE:
cpe:2.3:a:gstreamer:gstreamer:0.10.7:*:*:*:*:*:*:*
gstreamer
Version:
0.10.17
CPE:
cpe:2.3:a:gstreamer:gstreamer:0.10.17:*:*:*:*:*:*:*
gstreamer
Version:
0.10.21
CPE:
cpe:2.3:a:gstreamer:gstreamer:0.10.21:*:*:*:*:*:*:*
gstreamer
Version:
1.10.1
CPE:
cpe:2.3:a:gstreamer:gstreamer:1.10.1:*:*:*:*:*:*:*
This vulnerability affects 42 software configuration(s). Ensure you patch all affected systems.

Available Security Patches

3 patches available from vendors

View All Patches
Oracle

CPUAPR2026

Oracle Critical Patch Update Advisory - April 2026

Severity
Critical
Released
Apr 21, 2026
Restart Required
Security Update
Oracle

CPUJAN2026

Oracle Critical Patch Update Advisory - January 2026

Severity
Critical
Released
Jan 20, 2026
Restart Required
Security Update
SUSE

CVE-2025-47219

CVE-2025-47219

Severity
Unknown
Released
Jun 10, 2025
Security Update

Severity Details

8.1
out of 10.0
High

Weakness Type (CWE)

CWE-125 Top 25 #11

Out-of-bounds Read

Description
The product reads data past the end, or before the beginning, of the intended buffer.
Typical Severity
High
Abstraction Level
Base

Key Information

Published Date
August 07, 2025