Gpac
by Gpac
Source repositories
CVEs (423)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-38530 | Hig | 0.51 | 7.8 | 0.00 | Sep 6, 2022 | GPAC v2.1-DEV-rev232-gfcaa01ebb-master was discovered to contain a stack overflow when processing ISOM_IOD. | ||
| CVE-2022-24578 | Hig | 0.51 | 7.8 | 0.01 | Mar 14, 2022 | GPAC 1.0.1 is affected by a heap-based buffer overflow in SFS_AddString () at bifs/script_dec.c. | ||
| CVE-2022-24577 | Hig | 0.51 | 7.8 | 0.01 | Mar 14, 2022 | GPAC 1.0.1 is affected by a NULL pointer dereference in gf_utf8_wcslen. (gf_utf8_wcslen is a renamed Unicode utf8_wcslen function.) | ||
| CVE-2022-24575 | Hig | 0.51 | 7.8 | 0.01 | Mar 14, 2022 | GPAC 1.0.1 is affected by a stack-based buffer overflow through MP4Box. | ||
| CVE-2022-26967 | Hig | 0.51 | 7.8 | 0.01 | Mar 12, 2022 | GPAC 2.0 allows a heap-based buffer overflow in gf_base64_encode. It can be triggered via MP4Box. | ||
| CVE-2021-36417 | Hig | 0.51 | 7.8 | 0.01 | Jan 12, 2022 | A heap-based buffer overflow vulnerability exists in GPAC v1.0.1 in the gf_isom_dovi_config_get function in MP4Box, which causes a denial of service or execute arbitrary code via a crafted file. | ||
| CVE-2021-36414 | Hig | 0.51 | 7.8 | 0.01 | Jan 10, 2022 | A heab-based buffer overflow vulnerability exists in MP4Box in GPAC 1.0.1 via media.c, which allows attackers to cause a denial of service or execute arbitrary code via a crafted file. | ||
| CVE-2021-36412 | Hig | 0.51 | 7.8 | 0.01 | Jan 10, 2022 | A heap-based buffer overflow vulnerability exists in MP4Box in GPAC 1.0.1 via the gp_rtp_builder_do_mpeg12_video function, which allows attackers to possibly have unspecified other impact via a crafted file in the MP4Box command, | ||
| CVE-2021-32271 | Hig | 0.51 | 7.8 | 0.01 | Sep 20, 2021 | An issue was discovered in gpac through 20200801. A stack-buffer-overflow exists in the function DumpRawUIConfig located in odf_dump.c. It allows an attacker to cause code Execution. | ||
| CVE-2019-12483 | Hig | 0.51 | 7.8 | 0.01 | May 30, 2019 | An issue was discovered in GPAC 0.7.1. There is a heap-based buffer overflow in the function ReadGF_IPMPX_RemoveToolNotificationListener in odf/ipmpx_code.c in libgpac.a, as demonstrated by MP4Box. | ||
| CVE-2019-11221 | Hig | 0.51 | 7.8 | 0.01 | Apr 15, 2019 | GPAC 0.7.1 has a buffer overflow issue in gf_import_message() in media_import.c. | ||
| CVE-2018-1000100 | Hig | 0.51 | 7.8 | 0.01 | Mar 6, 2018 | GPAC MP4Box version 0.7.1 and earlier contains a Buffer Overflow vulnerability in src/isomedia/avc_ext.c lines 2417 to 2420 that can result in Heap chunks being modified, this could lead to RCE. This attack appear to be exploitable via an attacker supplied MP4 file that when run… | ||
| CVE-2025-55657 | Hig | 0.49 | 7.5 | 0.00 | Jun 9, 2026 | A NULL pointer dereference in the gf_odf_vvc_cfg_write_bs function (odf/descriptors.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file. | ||
| CVE-2025-52293 | Hig | 0.49 | 7.5 | 0.00 | Jun 9, 2026 | A segmentation violaton in the gf_hevc_read_sps_bs_internal function (media_tools/av_parsers.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying crafted HEVC SPS data. | ||
| CVE-2025-52292 | Hig | 0.49 | 7.5 | 0.01 | Jun 9, 2026 | A stack buffer overflow in the filein_process function (in_file.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file. | ||
| CVE-2025-70307 | Hig | 0.49 | 7.5 | 0.00 | Jan 15, 2026 | A stack overflow in the dump_ttxt_sample function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted packet. | ||
| CVE-2025-70308 | Hig | 0.49 | 7.5 | 0.00 | Jan 15, 2026 | An out-of-bounds read in the GSF demuxer filter component of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted .gsf file. | ||
| CVE-2025-70304 | Hig | 0.49 | 7.5 | 0.00 | Jan 15, 2026 | A buffer overflow in the vobsub_get_subpic_duration() function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted packet. | ||
| CVE-2024-24266 | Hig | 0.49 | 7.5 | 0.01 | Feb 5, 2024 | gpac v2.2.1 was discovered to contain a Use-After-Free (UAF) vulnerability via the dasher_configure_pid function at /src/filters/dasher.c. | ||
| CVE-2024-24265 | Hig | 0.49 | 7.5 | 0.01 | Feb 5, 2024 | gpac v2.2.1 was discovered to contain a memory leak via the dst_props variable in the gf_filter_pid_merge_properties_internal function. |
- risk 0.51cvss 7.8epss 0.00
GPAC v2.1-DEV-rev232-gfcaa01ebb-master was discovered to contain a stack overflow when processing ISOM_IOD.
- risk 0.51cvss 7.8epss 0.01
GPAC 1.0.1 is affected by a heap-based buffer overflow in SFS_AddString () at bifs/script_dec.c.
- risk 0.51cvss 7.8epss 0.01
GPAC 1.0.1 is affected by a NULL pointer dereference in gf_utf8_wcslen. (gf_utf8_wcslen is a renamed Unicode utf8_wcslen function.)
- risk 0.51cvss 7.8epss 0.01
GPAC 1.0.1 is affected by a stack-based buffer overflow through MP4Box.
- risk 0.51cvss 7.8epss 0.01
GPAC 2.0 allows a heap-based buffer overflow in gf_base64_encode. It can be triggered via MP4Box.
- risk 0.51cvss 7.8epss 0.01
A heap-based buffer overflow vulnerability exists in GPAC v1.0.1 in the gf_isom_dovi_config_get function in MP4Box, which causes a denial of service or execute arbitrary code via a crafted file.
- risk 0.51cvss 7.8epss 0.01
A heab-based buffer overflow vulnerability exists in MP4Box in GPAC 1.0.1 via media.c, which allows attackers to cause a denial of service or execute arbitrary code via a crafted file.
- risk 0.51cvss 7.8epss 0.01
A heap-based buffer overflow vulnerability exists in MP4Box in GPAC 1.0.1 via the gp_rtp_builder_do_mpeg12_video function, which allows attackers to possibly have unspecified other impact via a crafted file in the MP4Box command,
- risk 0.51cvss 7.8epss 0.01
An issue was discovered in gpac through 20200801. A stack-buffer-overflow exists in the function DumpRawUIConfig located in odf_dump.c. It allows an attacker to cause code Execution.
- risk 0.51cvss 7.8epss 0.01
An issue was discovered in GPAC 0.7.1. There is a heap-based buffer overflow in the function ReadGF_IPMPX_RemoveToolNotificationListener in odf/ipmpx_code.c in libgpac.a, as demonstrated by MP4Box.
- risk 0.51cvss 7.8epss 0.01
GPAC 0.7.1 has a buffer overflow issue in gf_import_message() in media_import.c.
- risk 0.51cvss 7.8epss 0.01
GPAC MP4Box version 0.7.1 and earlier contains a Buffer Overflow vulnerability in src/isomedia/avc_ext.c lines 2417 to 2420 that can result in Heap chunks being modified, this could lead to RCE. This attack appear to be exploitable via an attacker supplied MP4 file that when run…
- risk 0.49cvss 7.5epss 0.00
A NULL pointer dereference in the gf_odf_vvc_cfg_write_bs function (odf/descriptors.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.
- risk 0.49cvss 7.5epss 0.00
A segmentation violaton in the gf_hevc_read_sps_bs_internal function (media_tools/av_parsers.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying crafted HEVC SPS data.
- risk 0.49cvss 7.5epss 0.01
A stack buffer overflow in the filein_process function (in_file.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.
- risk 0.49cvss 7.5epss 0.00
A stack overflow in the dump_ttxt_sample function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted packet.
- risk 0.49cvss 7.5epss 0.00
An out-of-bounds read in the GSF demuxer filter component of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted .gsf file.
- risk 0.49cvss 7.5epss 0.00
A buffer overflow in the vobsub_get_subpic_duration() function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted packet.
- risk 0.49cvss 7.5epss 0.01
gpac v2.2.1 was discovered to contain a Use-After-Free (UAF) vulnerability via the dasher_configure_pid function at /src/filters/dasher.c.
- risk 0.49cvss 7.5epss 0.01
gpac v2.2.1 was discovered to contain a memory leak via the dst_props variable in the gf_filter_pid_merge_properties_internal function.
Page 4 of 22