CVE-2025-65407: LIVE555 Streaming Media

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

A use-after-free in the MPEG1or2Demux::newElementaryStream() function of Live555 Streaming Media v2018.09.02 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MPEG Program stream.

Affected products

  • LIVE555 Streaming Media: version 2018-09-02 only

Published 2025-12-01. Last modified 2026-06-17.