VYPR

gpac

by Debian

Source repositories

CVEs (5)

  • CVE-2026-50810MedJul 7, 2026
    risk 0.29cvss 5.5epss 0.00

    A NULL pointer dereference in smooth_parse_stream_index() in src/media_tools/mpd.c in GPAC master HEAD before commit b35c61f104b85fbb16520ac2838d5d2ef70845b5 allows attackers to cause a denial of service

  • CVE-2026-15185LowJul 9, 2026
    risk 0.14cvss 3.3epss 0.00

    A vulnerability was determined in GPAC 26.03-DEV. This affects the function vobsub_read_idx of the file /src/media_tools/vobsub.c of the component MP4Box. Executing a manipulation of the argument num_langs can lead to out-of-bounds read. The attack needs to be launched locally.…

  • CVE-2025-15668LowJul 6, 2026
    risk 0.14cvss 3.3epss 0.00

    A vulnerability was identified in GPAC up to b40ce70f5. This issue affects the function sgpd_del_entry of the file src/isomedia/box_code_base.c of the component MP4Box. Such manipulation of the argument data leads to heap-based buffer overflow. Local access is required to…

  • CVE-2026-14801LowJul 6, 2026
    risk 0.14cvss 3.3epss 0.00

    A security vulnerability has been detected in GPAC 26.03-DEV-rev342-g80071f700-master. The impacted element is the function txtin_probe_duration of the file src/filters/load_text.c of the component TeXML File Handler. Such manipulation of the argument txml_timescale leads to…

  • CVE-2026-13523LowJun 29, 2026
    risk 0.14cvss 3.3epss 0.00

    A weakness has been identified in GPAC up to 26.02.0. This affects an unknown part of the file src/utils/base_encoding.c of the component ISOBMFF Parser. Executing a manipulation can lead to highly compressed data. The attack needs to be launched locally. The exploit has been…