VYPR

Gpac

by Gpac

Source repositories

CVEs (423)

  • CVE-2025-70309MedJan 15, 2026
    risk 0.36cvss 5.5epss 0.00

    A stack overflow in the pcmreframe_flush_packet function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted WAV file.

  • CVE-2025-70305MedJan 15, 2026
    risk 0.36cvss 5.5epss 0.00

    A stack overflow in the dmx_saf function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted .saf file.

  • CVE-2024-50665MedJan 23, 2025
    risk 0.36cvss 5.5epss 0.00

    gpac 2.4 contains a SEGV at src/isomedia/drm_sample.c:1562:96 in isom_cenc_get_sai_by_saiz_saio in MP4Box.

  • CVE-2023-50120MedJan 10, 2024
    risk 0.36cvss 5.5epss 0.00

    MP4Box GPAC version 2.3-DEV-rev636-gfbd7e13aa-master was discovered to contain an infinite loop in the function av1_uvlc at media_tools/av_parsers.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted MP4 file.

  • CVE-2023-47465MedDec 9, 2023
    risk 0.36cvss 5.5epss 0.00

    An issue in GPAC v.2.2.1 and before allows a local attacker to cause a denial of service (DoS) via the ctts_box_read function of file src/isomedia/box_code_base.c.

  • CVE-2023-48958MedDec 7, 2023
    risk 0.36cvss 5.5epss 0.00

    gpac 2.3-DEV-rev617-g671976fcc-master contains memory leaks in gf_mpd_resolve_url media_tools/mpd.c:4589.

  • CVE-2023-48039MedNov 20, 2023
    risk 0.36cvss 5.5epss 0.00

    GPAC 2.3-DEV-rev617-g671976fcc-master is vulnerable to memory leak in gf_mpd_parse_string media_tools/mpd.c:75.

  • CVE-2023-47384MedNov 14, 2023
    risk 0.36cvss 5.5epss 0.00

    MP4Box GPAC v2.3-DEV-rev617-g671976fcc-master was discovered to contain a memory leak in the function gf_isom_add_chapter at /isomedia/isom_write.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted MP4 file.

  • CVE-2023-42298MedOct 12, 2023
    risk 0.36cvss 5.5epss 0.00

    An issue in GPAC GPAC v.2.2.1 and before allows a local attacker to cause a denial of service via the Q_DecCoordOnUnitSphere function of file src/bifs/unquantize.c.

  • CVE-2023-41000MedSep 11, 2023
    risk 0.36cvss 5.5epss 0.00

    GPAC through 2.2.1 has a use-after-free vulnerability in the function gf_bifs_flush_command_list in bifs/memory_decoder.c.

  • CVE-2023-39562MedAug 28, 2023
    risk 0.36cvss 5.5epss 0.00

    GPAC v2.3-DEV-rev449-g5948e4f70-master was discovered to contain a heap-use-after-free via the gf_bs_align function at bitstream.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via supplying a crafted file.

  • CVE-2023-37767MedJul 11, 2023
    risk 0.36cvss 5.5epss 0.00

    GPAC v2.3-DEV-rev381-g817a848f6-master was discovered to contain a segmentation violation in the BM_ParseIndexValueReplace function at /lib/libgpac.so.

  • CVE-2023-37766MedJul 11, 2023
    risk 0.36cvss 5.5epss 0.00

    GPAC v2.3-DEV-rev381-g817a848f6-master was discovered to contain a segmentation violation in the gf_isom_remove_user_data function at /lib/libgpac.so.

  • CVE-2023-37765MedJul 11, 2023
    risk 0.36cvss 5.5epss 0.00

    GPAC v2.3-DEV-rev381-g817a848f6-master was discovered to contain a segmentation violation in the gf_dump_vrml_sffield function at /lib/libgpac.so.

  • CVE-2023-37174MedJul 11, 2023
    risk 0.36cvss 5.5epss 0.00

    GPAC v2.3-DEV-rev381-g817a848f6-master was discovered to contain a segmentation violation in the dump_isom_scene function at /mp4box/filedump.c.

  • CVE-2022-47662MedJan 5, 2023
    risk 0.36cvss 5.5epss 0.00

    GPAC MP4Box 2.1-DEV-rev649-ga8f438d20 has a segment fault (/stack overflow) due to infinite recursion in Media_GetSample isomedia/media.c:662

  • CVE-2022-47086MedJan 5, 2023
    risk 0.36cvss 5.5epss 0.00

    GPAC MP4Box v2.1-DEV-rev574-g9d5bb184b contains a segmentation violation via the function gf_sm_load_init_swf at scene_manager/swf_parse.c

  • CVE-2022-46490MedJan 5, 2023
    risk 0.36cvss 5.5epss 0.00

    GPAC version 2.1-DEV-rev505-gb9577e6ad-master was discovered to contain a memory leak via the afrt_box_read function at box_code_adobe.c.

  • CVE-2022-46489MedJan 5, 2023
    risk 0.36cvss 5.5epss 0.00

    GPAC version 2.1-DEV-rev505-gb9577e6ad-master was discovered to contain a memory leak via the gf_isom_box_parse_ex function at box_funcs.c.

  • CVE-2022-45204MedNov 29, 2022
    risk 0.36cvss 5.5epss 0.00

    GPAC v2.1-DEV-rev428-gcb8ae46c8-master was discovered to contain a memory leak via the function dimC_box_read at isomedia/box_code_3gpp.c.

Page 7 of 22