Gpac
by Gpac
Source repositories
CVEs (423)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-4202 | Med | 0.00 | 6.3 | 0.01 | Nov 29, 2022 | A vulnerability, which was classified as problematic, was found in GPAC 2.1-DEV-rev490-g68064e101-master. Affected is the function lsr_translate_coords of the file laser/lsr_dec.c. The manipulation leads to integer overflow. It is possible to launch the attack remotely. The… | ||
| CVE-2022-3957 | Med | 0.00 | 4.3 | 0.01 | Nov 11, 2022 | A vulnerability classified as problematic was found in GPAC. Affected by this vulnerability is the function svg_parse_preserveaspectratio of the file scenegraph/svg_attributes.c of the component SVG Parser. The manipulation leads to memory leak. The attack can be launched… | ||
| CVE-2022-3222 | Med | 0.00 | 5.5 | 0.01 | Sep 15, 2022 | Uncontrolled Recursion in GitHub repository gpac/gpac prior to 2.1.0-DEV. | ||
| CVE-2022-3178 | Hig | 0.00 | 7.8 | 0.00 | Sep 12, 2022 | Buffer Over-read in GitHub repository gpac/gpac prior to 2.1.0-DEV. | ||
| CVE-2022-2549 | Med | 0.00 | 5.5 | 0.01 | Jul 27, 2022 | NULL Pointer Dereference in GitHub repository gpac/gpac prior to v2.1.0-DEV. | ||
| CVE-2022-2454 | Hig | 0.00 | 7.8 | 0.00 | Jul 19, 2022 | Integer Overflow or Wraparound in GitHub repository gpac/gpac prior to 2.1-DEV. | ||
| CVE-2022-2453 | Hig | 0.00 | 7.8 | 0.00 | Jul 19, 2022 | Use After Free in GitHub repository gpac/gpac prior to 2.1-DEV. | ||
| CVE-2021-40592 | Med | 0.00 | 5.5 | 0.01 | Jun 8, 2022 | GPAC version before commit 71460d72ec07df766dab0a4d52687529f3efcf0a (version v1.0.1 onwards) contains loop with unreachable exit condition ('infinite loop') vulnerability in ISOBMFF reader filter, isoffin_read.c. Function isoffin_process() can result in DoS by infinite loop. To… | ||
| CVE-2022-1795 | Cri | 0.00 | 9.8 | 0.01 | May 18, 2022 | Use After Free in GitHub repository gpac/gpac prior to v2.1.0-DEV. | ||
| CVE-2022-29340 | Hig | 0.00 | 7.5 | 0.01 | May 5, 2022 | GPAC 2.1-DEV-rev87-g053aae8-master. has a Null Pointer Dereference vulnerability in gf_isom_parse_movie_boxes_internal due to improper return value handling of GF_SKIP_BOX, which causes a Denial of Service. This vulnerability was fixed in commit 37592ad. | ||
| CVE-2022-29339 | Hig | 0.00 | 7.5 | 0.01 | May 5, 2022 | In GPAC 2.1-DEV-rev87-g053aae8-master, function BS_ReadByte() in utils/bitstream.c has a failed assertion, which causes a Denial of Service. This vulnerability was fixed in commit 9ea93a2. | ||
| CVE-2022-1441 | Hig | 0.00 | 7.8 | 0.01 | Apr 25, 2022 | MP4Box is a component of GPAC-2.0.0, which is a widely-used third-party package on RPM Fusion. When MP4Box tries to parse a MP4 file, it calls the function `diST_box_read()` to read from video. In this function, it allocates a buffer `str` with fixed length. However, content… | ||
| CVE-2022-1222 | Med | 0.00 | 5.5 | 0.01 | Apr 4, 2022 | Inf loop in GitHub repository gpac/gpac prior to 2.1.0-DEV. | ||
| CVE-2022-1172 | Med | 0.00 | 5.0 | 0.01 | Mar 30, 2022 | Null Pointer Dereference Caused Segmentation Fault in GitHub repository gpac/gpac prior to 2.1.0-DEV. | ||
| CVE-2022-1035 | Med | 0.00 | 5.5 | 0.01 | Mar 21, 2022 | Segmentation Fault caused by MP4Box -lsr in GitHub repository gpac/gpac prior to 2.1.0-DEV. | ||
| CVE-2021-4043 | Med | 0.00 | 5.5 | 0.05 | Feb 4, 2022 | NULL Pointer Dereference in GitHub repository gpac/gpac prior to 1.1.0. | ||
| CVE-2021-40576 | Med | 0.00 | 5.5 | 0.01 | Jan 13, 2022 | The binary MP4Box in Gpac 1.0.1 has a null pointer dereference vulnerability in the gf_isom_get_payt_count function in hint_track.c, which allows attackers to cause a denial of service. | ||
| CVE-2021-40575 | Med | 0.00 | 5.5 | 0.01 | Jan 13, 2022 | The binary MP4Box in Gpac 1.0.1 has a null pointer dereference vulnerability in the mpgviddmx_process function in reframe_mpgvid.c, which allows attackers to cause a denial of service. This vulnerability is possibly due to an incomplete fix for CVE-2021-40566. | ||
| CVE-2021-40574 | Hig | 0.00 | 7.8 | 0.01 | Jan 13, 2022 | The binary MP4Box in Gpac from 0.9.0-preview to 1.0.1 has a double-free vulnerability in the gf_text_get_utf8_line function in load_text.c, which allows attackers to cause a denial of service, even code execution and escalation of privileges. | ||
| CVE-2021-40573 | Med | 0.00 | 5.5 | 0.01 | Jan 13, 2022 | The binary MP4Box in Gpac 1.0.1 has a double-free vulnerability in the gf_list_del function in list.c, which allows attackers to cause a denial of service. |
- risk 0.00cvss 6.3epss 0.01
A vulnerability, which was classified as problematic, was found in GPAC 2.1-DEV-rev490-g68064e101-master. Affected is the function lsr_translate_coords of the file laser/lsr_dec.c. The manipulation leads to integer overflow. It is possible to launch the attack remotely. The…
- risk 0.00cvss 4.3epss 0.01
A vulnerability classified as problematic was found in GPAC. Affected by this vulnerability is the function svg_parse_preserveaspectratio of the file scenegraph/svg_attributes.c of the component SVG Parser. The manipulation leads to memory leak. The attack can be launched…
- risk 0.00cvss 5.5epss 0.01
Uncontrolled Recursion in GitHub repository gpac/gpac prior to 2.1.0-DEV.
- risk 0.00cvss 7.8epss 0.00
Buffer Over-read in GitHub repository gpac/gpac prior to 2.1.0-DEV.
- risk 0.00cvss 5.5epss 0.01
NULL Pointer Dereference in GitHub repository gpac/gpac prior to v2.1.0-DEV.
- risk 0.00cvss 7.8epss 0.00
Integer Overflow or Wraparound in GitHub repository gpac/gpac prior to 2.1-DEV.
- risk 0.00cvss 7.8epss 0.00
Use After Free in GitHub repository gpac/gpac prior to 2.1-DEV.
- risk 0.00cvss 5.5epss 0.01
GPAC version before commit 71460d72ec07df766dab0a4d52687529f3efcf0a (version v1.0.1 onwards) contains loop with unreachable exit condition ('infinite loop') vulnerability in ISOBMFF reader filter, isoffin_read.c. Function isoffin_process() can result in DoS by infinite loop. To…
- risk 0.00cvss 9.8epss 0.01
Use After Free in GitHub repository gpac/gpac prior to v2.1.0-DEV.
- risk 0.00cvss 7.5epss 0.01
GPAC 2.1-DEV-rev87-g053aae8-master. has a Null Pointer Dereference vulnerability in gf_isom_parse_movie_boxes_internal due to improper return value handling of GF_SKIP_BOX, which causes a Denial of Service. This vulnerability was fixed in commit 37592ad.
- risk 0.00cvss 7.5epss 0.01
In GPAC 2.1-DEV-rev87-g053aae8-master, function BS_ReadByte() in utils/bitstream.c has a failed assertion, which causes a Denial of Service. This vulnerability was fixed in commit 9ea93a2.
- risk 0.00cvss 7.8epss 0.01
MP4Box is a component of GPAC-2.0.0, which is a widely-used third-party package on RPM Fusion. When MP4Box tries to parse a MP4 file, it calls the function `diST_box_read()` to read from video. In this function, it allocates a buffer `str` with fixed length. However, content…
- risk 0.00cvss 5.5epss 0.01
Inf loop in GitHub repository gpac/gpac prior to 2.1.0-DEV.
- risk 0.00cvss 5.0epss 0.01
Null Pointer Dereference Caused Segmentation Fault in GitHub repository gpac/gpac prior to 2.1.0-DEV.
- risk 0.00cvss 5.5epss 0.01
Segmentation Fault caused by MP4Box -lsr in GitHub repository gpac/gpac prior to 2.1.0-DEV.
- risk 0.00cvss 5.5epss 0.05
NULL Pointer Dereference in GitHub repository gpac/gpac prior to 1.1.0.
- risk 0.00cvss 5.5epss 0.01
The binary MP4Box in Gpac 1.0.1 has a null pointer dereference vulnerability in the gf_isom_get_payt_count function in hint_track.c, which allows attackers to cause a denial of service.
- risk 0.00cvss 5.5epss 0.01
The binary MP4Box in Gpac 1.0.1 has a null pointer dereference vulnerability in the mpgviddmx_process function in reframe_mpgvid.c, which allows attackers to cause a denial of service. This vulnerability is possibly due to an incomplete fix for CVE-2021-40566.
- risk 0.00cvss 7.8epss 0.01
The binary MP4Box in Gpac from 0.9.0-preview to 1.0.1 has a double-free vulnerability in the gf_text_get_utf8_line function in load_text.c, which allows attackers to cause a denial of service, even code execution and escalation of privileges.
- risk 0.00cvss 5.5epss 0.01
The binary MP4Box in Gpac 1.0.1 has a double-free vulnerability in the gf_list_del function in list.c, which allows attackers to cause a denial of service.
Page 18 of 22