Search Results (3 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-5674 2 Pipewire, Redhat 3 Pipewire, Enterprise Linux, Enterprise Linux Eus 2026-08-06 8.8 High
A flaw was found in PipeWire, a multimedia server. This vulnerability allows an attacker to escape sandboxed applications, such as Flatpak, by exploiting PipeWire's PulseAudio compatibility layer. An attacker with minimal permissions within a sandboxed environment can load a malicious library, leading to arbitrary code execution outside the sandbox and potential compromise of the user's system.
CVE-2026-14324 2 Pipewire, Redhat 2 Pipewire, Enterprise Linux 2026-07-29 6.5 Medium
RAOP module accepts unbounded Content-Length values and does not check the pw_array_add() return.
CVE-2026-14330 2 Pipewire, Redhat 2 Pipewire, Enterprise Linux 2026-07-29 5.5 Medium
Multiple unbounded alloca() calls in the PulseAudio protocol server.