UxPlay 1.72 contains a double free vulnerability in its RTSP request handling. A specially crafted RTSP TEARDOWN request can trigger multiple calls to free() on the same memory address, potentially causing a Denial of Service.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-60458.json"
[ { "events": [ { "introduced": "0" }, { "last_affected": "1.72" } ] } ]