Streaming Media

Vendor:

First CVE: Jan 23, 2014 · Active for 12 years

13
Total CVEs
More Total CVEs than 92% of tracked products
3.3
Avg CVEs / Year
Higher CVE frequency than 84% of tracked products
7.7
Avg CVSS
Higher Avg CVSS than 64% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Streaming Media over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 23, 2014
12 years ago
Most Recent CVE
Dec 1, 2025
239 days ago

CVE Severity & Scoring

Streaming Media13 CVEs
All CVEs353,173 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network11 (84.6%)
Unknown2 (15.4%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (84.6%)
High0 (0.0%)
Unknown2 (15.4%)
User Interaction
None6 (46.2%)
Unknown2 (15.4%)
Required5 (38.5%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None11 (84.6%)
Unknown2 (15.4%)

Top CVEs

Signals from CVEs in this product scope (13 CVEs).

13 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The parseRTSPRequestString function in Live Networks Live555 Streaming Media 2013.11.26, as used in VideoLAN VLC Media Player, allows remote attackers to cause a denial of service
Jan 23, 20147.536NONO
In Live555 before 2019.02.27, malformed headers lead to invalid memory access in the parseAuthorizationHeader function.
Feb 28, 20199.831NONO
liblivemedia in Live555 before 2019.02.03 mishandles the termination of an RTSP stream after RTP/RTCP-over-RTSP has been set up, which could lead to a Use-After-Free error that cau
Feb 4, 20199.831NONO
The parseRTSPRequestString function in Live Networks Live555 Streaming Media 2011.08.13 through 2013.11.25, as used in VideoLAN VLC Media Player, allows remote attackers to cause a
Jan 23, 20147.530NONO
Live555 before 2019.08.16 has a Use-After-Free because GenericMediaServer::createNewClientSessionWithId can generate the same client session ID in succession, which is mishandled b
Aug 20, 20199.829NONO
Vulnerability in the AC3AudioFileServerMediaSubsession, ADTSAudioFileServerMediaSubsession, and AMRAudioFileServerMediaSubsessionLive OnDemandServerMediaSubsession subclasses in Ne
Apr 29, 20217.524NONO
A use-after-free in the ADTSAudioFileSource::samplingFrequency() function of Live555 Streaming Media v2018.09.02 allows attackers to cause a Denial of Service (DoS) via supplying a
Dec 1, 20256.523NONO
A buffer overflow in the getSideInfo2() function of Live555 Streaming Media v2018.09.02 allows attackers to cause a Denial of Service (DoS) via a crafted MP3 stream.
Dec 1, 20256.523NONO
In Live555 0.95, a setup packet can cause a memory leak leading to DoS because, when there are multiple instances of a single field (username, realm, nonce, uri, or response), only
Feb 11, 20197.523NONO
A use-after-free in the MPEG1or2Demux::newElementaryStream() function of Live555 Streaming Media v2018.09.02 allows attackers to cause a Denial of Service (DoS) via supplying a cra
Dec 1, 20256.522NONO

Exploit Exposure

Signals from CVEs in this product scope (13 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (13 CVEs).

Media Mentions

Signals from CVEs in this product scope (13 CVEs).

Top CNAs Publishing CVEs For Streaming Media

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2018-09-0256.50.3%00
2013-11-2617.528.2%00
2013-11-2517.517.4%00
2013-11-1517.517.4%00
2013-11-1417.517.4%00
2013-11-1017.517.4%00
2013-11-0617.517.4%00
2013-10-2517.517.4%00
2013-10-2417.517.4%00
2013-10-2217.517.4%00
2013-10-1817.517.4%00
2013-10-1617.517.4%00
2013-10-1117.517.4%00
2013-10-0917.517.4%00
2013-10-0817.517.4%00
2013-10-0717.517.4%00
2013-10-0317.517.4%00
2013-10-0217.517.4%00
2013-10-0117.517.4%00
2013-09-3017.517.4%00