Skip to main content

Threats Tagged 'cve-2026-19389'

View all threats tagged with 'cve-2026-19389'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2026-19389

Threats Tagged 'cve-2026-19389'

Click on any threat for detailed analysis and mitigation recommendations

A security vulnerability (CVE-2026-19389) has been identified in the gstreamer1-plugins-ugly-free package of the GStreamer streaming media framework. The flaw is an integer overflow/underflow in asfdemux bounds checks that can lead to an out-of-bounds read. Red Hat has issued an important security update for Red Hat Enterprise Linux 10 to address this issue. The vulnerability is rated with high severity by the source, though no CVSS score is provided. The update is available for multiple architectures including x86_64, ppc64le, and aarch64. Users of affected Red Hat Enterprise Linux 10 versions are advised to apply the update as detailed in the Red Hat advisory.

Join the discussion

A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/DVI ADPCM audio. Insufficient validation of the per-block sample count for multi-channel streams allows a crafted WAV file to cause writes beyond the allocated output buffer. This can lead to application crash, denial of service, memory corruption, or potentially arbitrary code execution when untrusted media is processed.

Join the discussion

Multiple integer overflow and underflow vulnerabilities were found in the GStreamer gst-plugins-ugly ASF demuxer (asfdemux) when parsing header objects from crafted ASF, WMV, or WMA files. Insufficient validation of attacker-controlled length and size values can bypass bounds checks and cause out-of-bounds heap reads. This can result in application crash, denial of service, or limited information disclosure when untrusted media is processed.

Join the discussion

Showing 1 to 3 of 3 results

Filters:Tag: cve-2026-19389
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses