VYPR

Vendor CVEs

Gpac

All CVEs

430 total · sorted by risk
  • CVE-2022-47093HigJan 5, 2023
    risk 0.51cvss 7.8epss 0.00

    GPAC MP4box 2.1-DEV-rev574-g9d5bb184b is vulnerable to heap use-after-free via filters/dmx_m2ts.c:470 in m2tsdmx_declare_pid

  • CVE-2022-47091HigJan 5, 2023
    risk 0.51cvss 7.8epss 0.00

    GPAC MP4box 2.1-DEV-rev574-g9d5bb184b is vulnerable to Buffer Overflow in gf_text_process_sub function of filters/load_text.c

  • CVE-2022-47089HigJan 5, 2023
    risk 0.51cvss 7.8epss 0.00

    GPAC MP4box 2.1-DEV-rev574-g9d5bb184b is vulnerable to Buffer Overflow via gf_vvc_read_sps_bs_internal function of media_tools/av_parsers.c

  • CVE-2022-47088HigJan 5, 2023
    risk 0.51cvss 7.8epss 0.00

    GPAC MP4box 2.1-DEV-rev574-g9d5bb184b is vulnerable to Buffer Overflow.

  • CVE-2022-47087HigJan 5, 2023
    risk 0.51cvss 7.8epss 0.00

    GPAC MP4box 2.1-DEV-rev574-g9d5bb184b has a Buffer overflow in gf_vvc_read_pps_bs_internal function of media_tools/av_parsers.c

  • CVE-2022-45283HigDec 6, 2022
    risk 0.51cvss 7.8epss 0.00

    GPAC MP4box v2.0.0 was discovered to contain a stack overflow in the smil_parse_time_list parameter at /scenegraph/svg_attributes.c.

  • CVE-2022-45343HigNov 29, 2022
    risk 0.51cvss 7.8epss 0.00

    GPAC v2.1-DEV-rev478-g696e6f868-master was discovered to contain a heap use-after-free via the Q_IsTypeOn function at /gpac/src/bifs/unquantize.c.

  • CVE-2022-45202HigNov 29, 2022
    risk 0.51cvss 7.8epss 0.00

    GPAC v2.1-DEV-rev428-gcb8ae46c8-master was discovered to contain a stack overflow via the function dimC_box_read at isomedia/box_code_3gpp.c.

  • CVE-2022-43042HigOct 19, 2022
    risk 0.51cvss 7.8epss 0.00

    GPAC 2.1-DEV-rev368-gfd054169b-master was discovered to contain a heap buffer overflow via the function FixSDTPInTRAF at isomedia/isom_intern.c.

  • CVE-2022-43040HigOct 19, 2022
    risk 0.51cvss 7.8epss 0.00

    GPAC 2.1-DEV-rev368-gfd054169b-master was discovered to contain a heap buffer overflow via the function gf_isom_box_dump_start_ex at /isomedia/box_funcs.c.

  • CVE-2022-38530HigSep 6, 2022
    risk 0.51cvss 7.8epss 0.00

    GPAC v2.1-DEV-rev232-gfcaa01ebb-master was discovered to contain a stack overflow when processing ISOM_IOD.

  • CVE-2022-24578HigMar 14, 2022
    risk 0.51cvss 7.8epss 0.01

    GPAC 1.0.1 is affected by a heap-based buffer overflow in SFS_AddString () at bifs/script_dec.c.

  • CVE-2022-24577HigMar 14, 2022
    risk 0.51cvss 7.8epss 0.01

    GPAC 1.0.1 is affected by a NULL pointer dereference in gf_utf8_wcslen. (gf_utf8_wcslen is a renamed Unicode utf8_wcslen function.)

  • CVE-2022-24575HigMar 14, 2022
    risk 0.51cvss 7.8epss 0.01

    GPAC 1.0.1 is affected by a stack-based buffer overflow through MP4Box.

  • CVE-2022-26967HigMar 12, 2022
    risk 0.51cvss 7.8epss 0.01

    GPAC 2.0 allows a heap-based buffer overflow in gf_base64_encode. It can be triggered via MP4Box.

  • CVE-2021-36417HigJan 12, 2022
    risk 0.51cvss 7.8epss 0.01

    A heap-based buffer overflow vulnerability exists in GPAC v1.0.1 in the gf_isom_dovi_config_get function in MP4Box, which causes a denial of service or execute arbitrary code via a crafted file.

  • CVE-2021-36414HigJan 10, 2022
    risk 0.51cvss 7.8epss 0.01

    A heab-based buffer overflow vulnerability exists in MP4Box in GPAC 1.0.1 via media.c, which allows attackers to cause a denial of service or execute arbitrary code via a crafted file.

  • CVE-2021-36412HigJan 10, 2022
    risk 0.51cvss 7.8epss 0.01

    A heap-based buffer overflow vulnerability exists in MP4Box in GPAC 1.0.1 via the gp_rtp_builder_do_mpeg12_video function, which allows attackers to possibly have unspecified other impact via a crafted file in the MP4Box command,

  • CVE-2021-32271HigSep 20, 2021
    risk 0.51cvss 7.8epss 0.01

    An issue was discovered in gpac through 20200801. A stack-buffer-overflow exists in the function DumpRawUIConfig located in odf_dump.c. It allows an attacker to cause code Execution.

  • CVE-2019-12483HigMay 30, 2019
    risk 0.51cvss 7.8epss 0.01

    An issue was discovered in GPAC 0.7.1. There is a heap-based buffer overflow in the function ReadGF_IPMPX_RemoveToolNotificationListener in odf/ipmpx_code.c in libgpac.a, as demonstrated by MP4Box.

  • CVE-2019-11221HigApr 15, 2019
    risk 0.51cvss 7.8epss 0.01

    GPAC 0.7.1 has a buffer overflow issue in gf_import_message() in media_import.c.

  • CVE-2018-1000100HigMar 6, 2018
    risk 0.51cvss 7.8epss 0.01

    GPAC MP4Box version 0.7.1 and earlier contains a Buffer Overflow vulnerability in src/isomedia/avc_ext.c lines 2417 to 2420 that can result in Heap chunks being modified, this could lead to RCE. This attack appear to be exploitable via an attacker supplied MP4 file that when run…

  • CVE-2025-55657HigJun 9, 2026
    risk 0.49cvss 7.5epss 0.00

    A NULL pointer dereference in the gf_odf_vvc_cfg_write_bs function (odf/descriptors.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.

  • CVE-2025-52293HigJun 9, 2026
    risk 0.49cvss 7.5epss 0.00

    A segmentation violaton in the gf_hevc_read_sps_bs_internal function (media_tools/av_parsers.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying crafted HEVC SPS data.

  • CVE-2025-52292HigJun 9, 2026
    risk 0.49cvss 7.5epss 0.01

    A stack buffer overflow in the filein_process function (in_file.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.

  • CVE-2025-70307HigJan 15, 2026
    risk 0.49cvss 7.5epss 0.00

    A stack overflow in the dump_ttxt_sample function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted packet.

  • CVE-2025-70308HigJan 15, 2026
    risk 0.49cvss 7.5epss 0.00

    An out-of-bounds read in the GSF demuxer filter component of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted .gsf file.

  • CVE-2025-70304HigJan 15, 2026
    risk 0.49cvss 7.5epss 0.00

    A buffer overflow in the vobsub_get_subpic_duration() function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted packet.

  • CVE-2024-24266HigFeb 5, 2024
    risk 0.49cvss 7.5epss 0.01

    gpac v2.2.1 was discovered to contain a Use-After-Free (UAF) vulnerability via the dasher_configure_pid function at /src/filters/dasher.c.

  • CVE-2024-24265HigFeb 5, 2024
    risk 0.49cvss 7.5epss 0.01

    gpac v2.2.1 was discovered to contain a memory leak via the dst_props variable in the gf_filter_pid_merge_properties_internal function.

  • CVE-2022-36186HigAug 17, 2022
    risk 0.49cvss 7.5epss 0.01

    A Null Pointer dereference vulnerability exists in GPAC 2.1-DEV-revUNKNOWN-master via the function gf_filter_pid_set_property_full () at filter_core/filter_pid.c:5250,which causes a Denial of Service (DoS). This vulnerability was fixed in commit b43f9d1.

  • CVE-2021-45266HigDec 22, 2021
    risk 0.49cvss 7.5epss 0.01

    A null pointer dereference vulnerability exists in gpac 1.1.0 via the lsr_read_anim_values_ex function, which causes a segmentation fault and application crash.

  • CVE-2021-41459HigOct 1, 2021
    risk 0.49cvss 7.5epss 0.01

    There is a stack buffer overflow in MP4Box v1.0.1 at src/filters/dmx_nhml.c:1008 in the nhmldmx_send_sample() function szXmlFrom parameter which leads to a denial of service vulnerability.

  • CVE-2021-41457HigOct 1, 2021
    risk 0.49cvss 7.5epss 0.01

    There is a stack buffer overflow in MP4Box 1.1.0 at src/filters/dmx_nhml.c in nhmldmx_init_parsing which leads to a denial of service vulnerability.

  • CVE-2021-41456HigOct 1, 2021
    risk 0.49cvss 7.5epss 0.01

    There is a stack buffer overflow in MP4Box v1.0.1 at src/filters/dmx_nhml.c:1004 in the nhmldmx_send_sample() function szXmlTo parameter which leads to a denial of service vulnerability.

  • CVE-2020-19750HigSep 7, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in gpac 0.8.0. The strdup function in box_code_base.c has a heap-based buffer over-read.

  • CVE-2019-13618HigJul 16, 2019
    risk 0.49cvss 7.5epss 0.02

    In GPAC before 0.8.0, isomedia/isom_read.c in libgpac.a has a heap-based buffer over-read, as demonstrated by a crash in gf_m2ts_sync in media_tools/mpegts.c.

  • CVE-2019-12482HigMay 30, 2019
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in GPAC 0.7.1. There is a NULL pointer dereference in the function gf_isom_get_original_format_type at isomedia/drm_sample.c in libgpac.a, as demonstrated by MP4Box.

  • CVE-2024-28318HigMar 15, 2024
    risk 0.46cvss 7.1epss 0.01

    gpac 2.3-DEV-rev921-g422b78ecf-master was discovered to contain a out of boundary write vulnerability via swf_get_string at scene_manager/swf_parse.c:325

  • CVE-2023-48090HigNov 20, 2023
    risk 0.46cvss 7.1epss 0.00

    GPAC 2.3-DEV-rev617-g671976fcc-master is vulnerable to memory leaks in extract_attributes media_tools/m3u8.c:329.

  • CVE-2022-47092HigJan 5, 2023
    risk 0.46cvss 7.1epss 0.00

    GPAC MP4box 2.1-DEV-rev574-g9d5bb184b is contains an Integer overflow vulnerability in gf_hevc_read_sps_bs_internal function of media_tools/av_parsers.c:8316

  • CVE-2022-30976HigMay 18, 2022
    risk 0.46cvss 7.1epss 0.01

    GPAC 2.0.0 misuses a certain Unicode utf8_wcslen (renamed gf_utf8_wcslen) function in utils/utf.c, resulting in a heap-based buffer over-read, as demonstrated by MP4Box.

  • CVE-2020-23267HigSep 22, 2021
    risk 0.46cvss 7.1epss 0.01

    An issue was discovered in gpac 0.8.0. The gf_hinter_track_process function in isom_hinter_track_process.c has a heap-based buffer overflow which can lead to a denial of service (DOS) via a crafted media file

  • CVE-2025-60464HigJun 25, 2026
    risk 0.44cvss 7.8epss 0.00

    A use-after-free in the gf_sei_load_from_state_internal function (/filters/sei_load.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MPEG-2 TS file.

  • CVE-2022-47090HigJan 24, 2025
    risk 0.44cvss 7.8epss 0.00

    GPAC MP4box 2.1-DEV-rev574-g9d5bb184b contains a buffer overflow in gf_vvc_read_pps_bs_internal function of media_tools/av_parsers.c, check needed for num_exp_tile_columns

  • CVE-2020-35982HigApr 21, 2021
    risk 0.44cvss 7.8epss 0.01

    An issue was discovered in GPAC version 0.8.0 and 1.0.1. There is an invalid pointer dereference in the function gf_hinter_track_finalize() in media_tools/isom_hinter.c.

  • CVE-2020-35981HigApr 21, 2021
    risk 0.44cvss 7.8epss 0.01

    An issue was discovered in GPAC version 0.8.0 and 1.0.1. There is an invalid pointer dereference in the function SetupWriters() in isomedia/isom_store.c.

  • CVE-2020-35980HigApr 21, 2021
    risk 0.44cvss 7.8epss 0.01

    An issue was discovered in GPAC version 0.8.0 and 1.0.1. There is a use-after-free in the function gf_isom_box_del() in isomedia/box_funcs.c.

  • CVE-2020-35979HigApr 21, 2021
    risk 0.44cvss 7.8epss 0.01

    An issue was discovered in GPAC version 0.8.0 and 1.0.1. There is heap-based buffer overflow in the function gp_rtp_builder_do_avc() in ietf/rtp_pck_mpeg4.c.

  • CVE-2025-60474HigJun 24, 2026
    risk 0.42cvss 7.5epss 0.01

    A buffer overflow in the gf_media_import function (/media_tools/av_parsers.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.

Page 2 of 9