VYPR

Gpac

by Gpac

Source repositories

CVEs (423)

  • CVE-2026-10565LowJun 2, 2026
    risk 0.13cvss 3.1epss 0.00

    A security flaw has been discovered in Open5GS up to 2.7.6. The impacted element is the function gmm_state_security_mode of the file src/amf/gmm-sm.c of the component NGAP Handover. Performing a manipulation results in race condition. The attack can be initiated remotely. The…

  • CVE-2026-27821HigFeb 26, 2026
    risk 0.00cvss 7.8epss 0.00

    GPAC is an open-source multimedia framework. In versions up to and including 26.02.0, a stack buffer overflow occurs during NHML file parsing in `src/filters/dmx_nhml.c`. The value of the xmlHeaderEnd XML attribute is copied from att->value into szXmlHeaderEnd[1000] using…

  • CVE-2025-7797MedJul 18, 2025
    risk 0.00cvss 5.3epss 0.01

    A vulnerability was found in GPAC up to 2.4. It has been rated as problematic. Affected by this issue is the function gf_dash_download_init_segment of the file src/media_tools/dash_client.c. The manipulation of the argument base_init_url leads to null pointer dereference. The…

  • CVE-2025-25723HigFeb 28, 2025
    risk 0.00cvss 8.4epss 0.00

    Buffer Overflow vulnerability in GPAC version 2.5 allows a local attacker to execute arbitrary code.

  • CVE-2024-57184MedJan 24, 2025
    risk 0.00cvss 5.5epss 0.00

    An issue was discovered in GPAC v0.8.0, as demonstrated by MP4Box. It contains a heap-based buffer overflow in gf_m2ts_process_pmt in media_tools/mpegts.c:2163 that can cause a denial of service (DOS) via a crafted MP4 file.

  • CVE-2023-4679MedNov 15, 2024
    risk 0.00cvss 5.5epss 0.00

    A use after free vulnerability exists in GPAC version 2.3-DEV-revrelease, specifically in the gf_filterpacket_del function in filter_core/filter.c at line 38. This vulnerability can lead to a double-free condition, which may cause the application to crash.

  • CVE-2024-6064MedJun 17, 2024
    risk 0.00cvss 5.3epss 0.00

    A vulnerability was found in GPAC 2.5-DEV-rev228-g11067ea92-master. It has been declared as problematic. This vulnerability affects the function xmt_node_end of the file src/scene_manager/loader_xmt.c of the component MP4Box. The manipulation leads to use after free. Local…

  • CVE-2024-6063LowJun 17, 2024
    risk 0.00cvss 3.3epss 0.00

    A vulnerability was found in GPAC 2.5-DEV-rev228-g11067ea92-master. It has been classified as problematic. This affects the function m2tsdmx_on_event of the file src/filters/dmx_m2ts.c of the component MP4Box. The manipulation leads to null pointer dereference. An attack has to…

  • CVE-2024-6062LowJun 17, 2024
    risk 0.00cvss 3.3epss 0.00

    A vulnerability was found in GPAC 2.5-DEV-rev228-g11067ea92-master and classified as problematic. Affected by this issue is the function swf_svg_add_iso_sample of the file src/filters/load_text.c of the component MP4Box. The manipulation leads to null pointer dereference. The…

  • CVE-2024-6061LowJun 17, 2024
    risk 0.00cvss 3.3epss 0.00

    A vulnerability has been found in GPAC 2.5-DEV-rev228-g11067ea92-master and classified as problematic. Affected by this vulnerability is the function isoffin_process of the file src/filters/isoffin_read.c of the component MP4Box. The manipulation leads to infinite loop. It is…

  • CVE-2024-24267HigFeb 5, 2024
    risk 0.00cvss 7.5epss 0.02

    gpac v2.2.1 (fixed in v2.4.0) was discovered to contain a memory leak via the gfio_blob variable in the gf_fileio_from_blob function.

  • CVE-2024-0322CriJan 8, 2024
    risk 0.00cvss 9.1epss 0.01

    Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.3-DEV.

  • CVE-2024-0321CriJan 8, 2024
    risk 0.00cvss 9.8epss 0.01

    Stack-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.3-DEV.

  • CVE-2023-46929HigJan 3, 2024
    risk 0.00cvss 7.5epss 0.01

    An issue discovered in GPAC 2.3-DEV-rev605-gfc9e29089-master in MP4Box in gf_avc_change_vui /afltest/gpac/src/media_tools/av_parsers.c:6872:55 allows attackers to crash the application.

  • CVE-2023-48014HigNov 15, 2023
    risk 0.00cvss 7.8epss 0.00

    GPAC v2.3-DEV-rev566-g50c2ab06f-master was discovered to contain a stack overflow via the hevc_parse_vps_extension function at /media_tools/av_parsers.c.

  • CVE-2023-48013HigNov 15, 2023
    risk 0.00cvss 7.8epss 0.00

    GPAC v2.3-DEV-rev566-g50c2ab06f-master was discovered to contain a double free via the gf_filterpacket_del function at /gpac/src/filter_core/filter.c.

  • CVE-2023-48011HigNov 15, 2023
    risk 0.00cvss 7.8epss 0.00

    GPAC v2.3-DEV-rev566-g50c2ab06f-master was discovered to contain a heap-use-after-free via the flush_ref_samples function at /gpac/src/isomedia/movie_fragments.c.

  • CVE-2023-46001MedNov 7, 2023
    risk 0.00cvss 5.5epss 0.00

    Buffer Overflow vulnerability in gpac MP4Box v.2.3-DEV-rev573-g201320819-master allows a local attacker to cause a denial of service via the gpac/src/isomedia/isom_read.c:2807:51 function in gf_isom_get_user_data.

  • CVE-2023-5998HigNov 7, 2023
    risk 0.00cvss 7.5epss 0.01

    Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.3.0-DEV.

  • CVE-2023-46928MedNov 1, 2023
    risk 0.00cvss 5.5epss 0.00

    GPAC 2.3-DEV-rev605-gfc9e29089-master contains a SEGV in gpac/MP4Box in gf_media_change_pl /afltest/gpac/src/media_tools/isom_tools.c:3293:42.

Page 15 of 22