Good Plug Ins
Vendor:
First CVE: Feb 2, 2009 · Active for 17 years
6
Total CVEs
More Total CVEs than 83% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 78% of tracked products
8.2
Avg CVSS
Higher Avg CVSS than 75% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Good Plug Ins over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 2, 2009
17 years ago
Most Recent CVE
May 14, 2026
75 days ago
CVE Severity & Scoring
Good Plug Ins6 CVEs
33%
50%
17%
All CVEs352,785 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (16.7%)
Network1 (16.7%)
Unknown4 (66.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (33.3%)
High0 (0.0%)
Unknown4 (66.7%)
User Interaction
None2 (33.3%)
Unknown4 (66.7%)
Required0 (0.0%)
Privileges Required
Low1 (16.7%)
High0 (0.0%)
None1 (16.7%)
Unknown4 (66.7%)
Top CVEs
Signals from CVEs in this product scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-46470CRITICAL An issue was discovered in GStreamer gst-plugins-good before 1.28.2. When parsing MP4 audio tracks, the isomp4 plugin's qtdemux_audio_caps function does not sufficiently validate a | May 14, 2026 | 9.1 | 31 | NO | NO |
CVE-2009-0397HIGH Heap-based buffer overflow in the qtdemux_parse_samples function in gst/qtdemux/qtdemux.c in GStreamer Good Plug-ins (aka gst-plugins-good) 0.10.9 through 0.10.11, and GStreamer Pl | Feb 3, 2009 | 9.3 | 26 | NO | NO |
CVE-2009-1932MEDIUM Multiple integer overflows in the (1) user_info_callback, (2) user_endrow_callback, and (3) gst_pngdec_task functions (ext/libpng/gstpngdec.c) in GStreamer Good Plug-ins (aka gst-p | Jun 4, 2009 | 6.8 | 25 | NO | NO |
CVE-2009-0387HIGH Array index error in the qtdemux_parse_samples function in gst/qtdemux/qtdemux.c in GStreamer Good Plug-ins (aka gst-plugins-good) 0.10.9 through 0.10.11 allows remote attackers to | Feb 2, 2009 | 9.3 | 25 | NO | NO |
CVE-2009-0386HIGH Heap-based buffer overflow in the qtdemux_parse_samples function in gst/qtdemux/qtdemux.c in GStreamer Good Plug-ins (aka gst-plugins-good) 0.10.9 through 0.10.11 might allow remot | Feb 2, 2009 | 9.3 | 25 | NO | NO |
CVE-2026-46469MEDIUM An issue was discovered in GStreamer gst-plugins-good before 1.28.2. When parsing MP4 audio tracks, the isomp4 plugin's qtdemux_parse_trak function does not sufficiently validate a | May 14, 2026 | 5.5 | 23 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (6 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (6 CVEs).
Media Mentions
Signals from CVEs in this product scope (6 CVEs).
Top CNAs Publishing CVEs For Good Plug Ins
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 0.10.9 | 3 | 9.3 | 7.0% | 0 | 0 |
| 0.10.15 | 1 | 6.8 | 5.5% | 0 | 0 |
| 0.10.11 | 3 | 9.3 | 7.0% | 0 | 0 |
| 0.10.10 | 3 | 9.3 | 7.0% | 0 | 0 |