Gpac
by Gpac
Source repositories
CVEs (423)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-10565 | Low | 0.13 | 3.1 | 0.00 | Jun 2, 2026 | A security flaw has been discovered in Open5GS up to 2.7.6. The impacted element is the function gmm_state_security_mode of the file src/amf/gmm-sm.c of the component NGAP Handover. Performing a manipulation results in race condition. The attack can be initiated remotely. The… | ||
| CVE-2026-27821 | Hig | 0.00 | 7.8 | 0.00 | Feb 26, 2026 | GPAC is an open-source multimedia framework. In versions up to and including 26.02.0, a stack buffer overflow occurs during NHML file parsing in `src/filters/dmx_nhml.c`. The value of the xmlHeaderEnd XML attribute is copied from att->value into szXmlHeaderEnd[1000] using… | ||
| CVE-2025-7797 | Med | 0.00 | 5.3 | 0.01 | Jul 18, 2025 | A vulnerability was found in GPAC up to 2.4. It has been rated as problematic. Affected by this issue is the function gf_dash_download_init_segment of the file src/media_tools/dash_client.c. The manipulation of the argument base_init_url leads to null pointer dereference. The… | ||
| CVE-2025-25723 | Hig | 0.00 | 8.4 | 0.00 | Feb 28, 2025 | Buffer Overflow vulnerability in GPAC version 2.5 allows a local attacker to execute arbitrary code. | ||
| CVE-2024-57184 | Med | 0.00 | 5.5 | 0.00 | Jan 24, 2025 | An issue was discovered in GPAC v0.8.0, as demonstrated by MP4Box. It contains a heap-based buffer overflow in gf_m2ts_process_pmt in media_tools/mpegts.c:2163 that can cause a denial of service (DOS) via a crafted MP4 file. | ||
| CVE-2023-4679 | Med | 0.00 | 5.5 | 0.00 | Nov 15, 2024 | A use after free vulnerability exists in GPAC version 2.3-DEV-revrelease, specifically in the gf_filterpacket_del function in filter_core/filter.c at line 38. This vulnerability can lead to a double-free condition, which may cause the application to crash. | ||
| CVE-2024-6064 | Med | 0.00 | 5.3 | 0.00 | Jun 17, 2024 | A vulnerability was found in GPAC 2.5-DEV-rev228-g11067ea92-master. It has been declared as problematic. This vulnerability affects the function xmt_node_end of the file src/scene_manager/loader_xmt.c of the component MP4Box. The manipulation leads to use after free. Local… | ||
| CVE-2024-6063 | Low | 0.00 | 3.3 | 0.00 | Jun 17, 2024 | A vulnerability was found in GPAC 2.5-DEV-rev228-g11067ea92-master. It has been classified as problematic. This affects the function m2tsdmx_on_event of the file src/filters/dmx_m2ts.c of the component MP4Box. The manipulation leads to null pointer dereference. An attack has to… | ||
| CVE-2024-6062 | Low | 0.00 | 3.3 | 0.00 | Jun 17, 2024 | A vulnerability was found in GPAC 2.5-DEV-rev228-g11067ea92-master and classified as problematic. Affected by this issue is the function swf_svg_add_iso_sample of the file src/filters/load_text.c of the component MP4Box. The manipulation leads to null pointer dereference. The… | ||
| CVE-2024-6061 | Low | 0.00 | 3.3 | 0.00 | Jun 17, 2024 | A vulnerability has been found in GPAC 2.5-DEV-rev228-g11067ea92-master and classified as problematic. Affected by this vulnerability is the function isoffin_process of the file src/filters/isoffin_read.c of the component MP4Box. The manipulation leads to infinite loop. It is… | ||
| CVE-2024-24267 | Hig | 0.00 | 7.5 | 0.02 | Feb 5, 2024 | gpac v2.2.1 (fixed in v2.4.0) was discovered to contain a memory leak via the gfio_blob variable in the gf_fileio_from_blob function. | ||
| CVE-2024-0322 | Cri | 0.00 | 9.1 | 0.01 | Jan 8, 2024 | Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.3-DEV. | ||
| CVE-2024-0321 | Cri | 0.00 | 9.8 | 0.01 | Jan 8, 2024 | Stack-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.3-DEV. | ||
| CVE-2023-46929 | Hig | 0.00 | 7.5 | 0.01 | Jan 3, 2024 | An issue discovered in GPAC 2.3-DEV-rev605-gfc9e29089-master in MP4Box in gf_avc_change_vui /afltest/gpac/src/media_tools/av_parsers.c:6872:55 allows attackers to crash the application. | ||
| CVE-2023-48014 | Hig | 0.00 | 7.8 | 0.00 | Nov 15, 2023 | GPAC v2.3-DEV-rev566-g50c2ab06f-master was discovered to contain a stack overflow via the hevc_parse_vps_extension function at /media_tools/av_parsers.c. | ||
| CVE-2023-48013 | Hig | 0.00 | 7.8 | 0.00 | Nov 15, 2023 | GPAC v2.3-DEV-rev566-g50c2ab06f-master was discovered to contain a double free via the gf_filterpacket_del function at /gpac/src/filter_core/filter.c. | ||
| CVE-2023-48011 | Hig | 0.00 | 7.8 | 0.00 | Nov 15, 2023 | GPAC v2.3-DEV-rev566-g50c2ab06f-master was discovered to contain a heap-use-after-free via the flush_ref_samples function at /gpac/src/isomedia/movie_fragments.c. | ||
| CVE-2023-46001 | Med | 0.00 | 5.5 | 0.00 | Nov 7, 2023 | Buffer Overflow vulnerability in gpac MP4Box v.2.3-DEV-rev573-g201320819-master allows a local attacker to cause a denial of service via the gpac/src/isomedia/isom_read.c:2807:51 function in gf_isom_get_user_data. | ||
| CVE-2023-5998 | Hig | 0.00 | 7.5 | 0.01 | Nov 7, 2023 | Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.3.0-DEV. | ||
| CVE-2023-46928 | Med | 0.00 | 5.5 | 0.00 | Nov 1, 2023 | GPAC 2.3-DEV-rev605-gfc9e29089-master contains a SEGV in gpac/MP4Box in gf_media_change_pl /afltest/gpac/src/media_tools/isom_tools.c:3293:42. |
- risk 0.13cvss 3.1epss 0.00
A security flaw has been discovered in Open5GS up to 2.7.6. The impacted element is the function gmm_state_security_mode of the file src/amf/gmm-sm.c of the component NGAP Handover. Performing a manipulation results in race condition. The attack can be initiated remotely. The…
- risk 0.00cvss 7.8epss 0.00
GPAC is an open-source multimedia framework. In versions up to and including 26.02.0, a stack buffer overflow occurs during NHML file parsing in `src/filters/dmx_nhml.c`. The value of the xmlHeaderEnd XML attribute is copied from att->value into szXmlHeaderEnd[1000] using…
- risk 0.00cvss 5.3epss 0.01
A vulnerability was found in GPAC up to 2.4. It has been rated as problematic. Affected by this issue is the function gf_dash_download_init_segment of the file src/media_tools/dash_client.c. The manipulation of the argument base_init_url leads to null pointer dereference. The…
- risk 0.00cvss 8.4epss 0.00
Buffer Overflow vulnerability in GPAC version 2.5 allows a local attacker to execute arbitrary code.
- risk 0.00cvss 5.5epss 0.00
An issue was discovered in GPAC v0.8.0, as demonstrated by MP4Box. It contains a heap-based buffer overflow in gf_m2ts_process_pmt in media_tools/mpegts.c:2163 that can cause a denial of service (DOS) via a crafted MP4 file.
- risk 0.00cvss 5.5epss 0.00
A use after free vulnerability exists in GPAC version 2.3-DEV-revrelease, specifically in the gf_filterpacket_del function in filter_core/filter.c at line 38. This vulnerability can lead to a double-free condition, which may cause the application to crash.
- risk 0.00cvss 5.3epss 0.00
A vulnerability was found in GPAC 2.5-DEV-rev228-g11067ea92-master. It has been declared as problematic. This vulnerability affects the function xmt_node_end of the file src/scene_manager/loader_xmt.c of the component MP4Box. The manipulation leads to use after free. Local…
- risk 0.00cvss 3.3epss 0.00
A vulnerability was found in GPAC 2.5-DEV-rev228-g11067ea92-master. It has been classified as problematic. This affects the function m2tsdmx_on_event of the file src/filters/dmx_m2ts.c of the component MP4Box. The manipulation leads to null pointer dereference. An attack has to…
- risk 0.00cvss 3.3epss 0.00
A vulnerability was found in GPAC 2.5-DEV-rev228-g11067ea92-master and classified as problematic. Affected by this issue is the function swf_svg_add_iso_sample of the file src/filters/load_text.c of the component MP4Box. The manipulation leads to null pointer dereference. The…
- risk 0.00cvss 3.3epss 0.00
A vulnerability has been found in GPAC 2.5-DEV-rev228-g11067ea92-master and classified as problematic. Affected by this vulnerability is the function isoffin_process of the file src/filters/isoffin_read.c of the component MP4Box. The manipulation leads to infinite loop. It is…
- risk 0.00cvss 7.5epss 0.02
gpac v2.2.1 (fixed in v2.4.0) was discovered to contain a memory leak via the gfio_blob variable in the gf_fileio_from_blob function.
- risk 0.00cvss 9.1epss 0.01
Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.3-DEV.
- risk 0.00cvss 9.8epss 0.01
Stack-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.3-DEV.
- risk 0.00cvss 7.5epss 0.01
An issue discovered in GPAC 2.3-DEV-rev605-gfc9e29089-master in MP4Box in gf_avc_change_vui /afltest/gpac/src/media_tools/av_parsers.c:6872:55 allows attackers to crash the application.
- risk 0.00cvss 7.8epss 0.00
GPAC v2.3-DEV-rev566-g50c2ab06f-master was discovered to contain a stack overflow via the hevc_parse_vps_extension function at /media_tools/av_parsers.c.
- risk 0.00cvss 7.8epss 0.00
GPAC v2.3-DEV-rev566-g50c2ab06f-master was discovered to contain a double free via the gf_filterpacket_del function at /gpac/src/filter_core/filter.c.
- risk 0.00cvss 7.8epss 0.00
GPAC v2.3-DEV-rev566-g50c2ab06f-master was discovered to contain a heap-use-after-free via the flush_ref_samples function at /gpac/src/isomedia/movie_fragments.c.
- risk 0.00cvss 5.5epss 0.00
Buffer Overflow vulnerability in gpac MP4Box v.2.3-DEV-rev573-g201320819-master allows a local attacker to cause a denial of service via the gpac/src/isomedia/isom_read.c:2807:51 function in gf_isom_get_user_data.
- risk 0.00cvss 7.5epss 0.01
Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.3.0-DEV.
- risk 0.00cvss 5.5epss 0.00
GPAC 2.3-DEV-rev605-gfc9e29089-master contains a SEGV in gpac/MP4Box in gf_media_change_pl /afltest/gpac/src/media_tools/isom_tools.c:3293:42.
Page 15 of 22