VYPR

Gpac

by Gpac

Source repositories

CVEs (423)

  • CVE-2022-38530HigSep 6, 2022
    risk 0.51cvss 7.8epss 0.00

    GPAC v2.1-DEV-rev232-gfcaa01ebb-master was discovered to contain a stack overflow when processing ISOM_IOD.

  • CVE-2022-24578HigMar 14, 2022
    risk 0.51cvss 7.8epss 0.01

    GPAC 1.0.1 is affected by a heap-based buffer overflow in SFS_AddString () at bifs/script_dec.c.

  • CVE-2022-24577HigMar 14, 2022
    risk 0.51cvss 7.8epss 0.01

    GPAC 1.0.1 is affected by a NULL pointer dereference in gf_utf8_wcslen. (gf_utf8_wcslen is a renamed Unicode utf8_wcslen function.)

  • CVE-2022-24575HigMar 14, 2022
    risk 0.51cvss 7.8epss 0.01

    GPAC 1.0.1 is affected by a stack-based buffer overflow through MP4Box.

  • CVE-2022-26967HigMar 12, 2022
    risk 0.51cvss 7.8epss 0.01

    GPAC 2.0 allows a heap-based buffer overflow in gf_base64_encode. It can be triggered via MP4Box.

  • CVE-2021-36417HigJan 12, 2022
    risk 0.51cvss 7.8epss 0.01

    A heap-based buffer overflow vulnerability exists in GPAC v1.0.1 in the gf_isom_dovi_config_get function in MP4Box, which causes a denial of service or execute arbitrary code via a crafted file.

  • CVE-2021-36414HigJan 10, 2022
    risk 0.51cvss 7.8epss 0.01

    A heab-based buffer overflow vulnerability exists in MP4Box in GPAC 1.0.1 via media.c, which allows attackers to cause a denial of service or execute arbitrary code via a crafted file.

  • CVE-2021-36412HigJan 10, 2022
    risk 0.51cvss 7.8epss 0.01

    A heap-based buffer overflow vulnerability exists in MP4Box in GPAC 1.0.1 via the gp_rtp_builder_do_mpeg12_video function, which allows attackers to possibly have unspecified other impact via a crafted file in the MP4Box command,

  • CVE-2021-32271HigSep 20, 2021
    risk 0.51cvss 7.8epss 0.01

    An issue was discovered in gpac through 20200801. A stack-buffer-overflow exists in the function DumpRawUIConfig located in odf_dump.c. It allows an attacker to cause code Execution.

  • CVE-2019-12483HigMay 30, 2019
    risk 0.51cvss 7.8epss 0.01

    An issue was discovered in GPAC 0.7.1. There is a heap-based buffer overflow in the function ReadGF_IPMPX_RemoveToolNotificationListener in odf/ipmpx_code.c in libgpac.a, as demonstrated by MP4Box.

  • CVE-2019-11221HigApr 15, 2019
    risk 0.51cvss 7.8epss 0.01

    GPAC 0.7.1 has a buffer overflow issue in gf_import_message() in media_import.c.

  • CVE-2018-1000100HigMar 6, 2018
    risk 0.51cvss 7.8epss 0.01

    GPAC MP4Box version 0.7.1 and earlier contains a Buffer Overflow vulnerability in src/isomedia/avc_ext.c lines 2417 to 2420 that can result in Heap chunks being modified, this could lead to RCE. This attack appear to be exploitable via an attacker supplied MP4 file that when run…

  • CVE-2025-55657HigJun 9, 2026
    risk 0.49cvss 7.5epss 0.00

    A NULL pointer dereference in the gf_odf_vvc_cfg_write_bs function (odf/descriptors.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.

  • CVE-2025-52293HigJun 9, 2026
    risk 0.49cvss 7.5epss 0.00

    A segmentation violaton in the gf_hevc_read_sps_bs_internal function (media_tools/av_parsers.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying crafted HEVC SPS data.

  • CVE-2025-52292HigJun 9, 2026
    risk 0.49cvss 7.5epss 0.01

    A stack buffer overflow in the filein_process function (in_file.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.

  • CVE-2025-70307HigJan 15, 2026
    risk 0.49cvss 7.5epss 0.00

    A stack overflow in the dump_ttxt_sample function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted packet.

  • CVE-2025-70308HigJan 15, 2026
    risk 0.49cvss 7.5epss 0.00

    An out-of-bounds read in the GSF demuxer filter component of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted .gsf file.

  • CVE-2025-70304HigJan 15, 2026
    risk 0.49cvss 7.5epss 0.00

    A buffer overflow in the vobsub_get_subpic_duration() function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted packet.

  • CVE-2024-24266HigFeb 5, 2024
    risk 0.49cvss 7.5epss 0.01

    gpac v2.2.1 was discovered to contain a Use-After-Free (UAF) vulnerability via the dasher_configure_pid function at /src/filters/dasher.c.

  • CVE-2024-24265HigFeb 5, 2024
    risk 0.49cvss 7.5epss 0.01

    gpac v2.2.1 was discovered to contain a memory leak via the dst_props variable in the gf_filter_pid_merge_properties_internal function.

Page 4 of 22