VYPR

Vendor CVEs

Gpac

All CVEs

430 total · sorted by risk
  • CVE-2022-3178HigSep 12, 2022
    risk 0.00cvss 7.8epss 0.00

    Buffer Over-read in GitHub repository gpac/gpac prior to 2.1.0-DEV.

  • CVE-2022-2549MedJul 27, 2022
    risk 0.00cvss 5.5epss 0.01

    NULL Pointer Dereference in GitHub repository gpac/gpac prior to v2.1.0-DEV.

  • CVE-2022-2454HigJul 19, 2022
    risk 0.00cvss 7.8epss 0.00

    Integer Overflow or Wraparound in GitHub repository gpac/gpac prior to 2.1-DEV.

  • CVE-2022-2453HigJul 19, 2022
    risk 0.00cvss 7.8epss 0.00

    Use After Free in GitHub repository gpac/gpac prior to 2.1-DEV.

  • CVE-2021-40592MedJun 8, 2022
    risk 0.00cvss 5.5epss 0.01

    GPAC version before commit 71460d72ec07df766dab0a4d52687529f3efcf0a (version v1.0.1 onwards) contains loop with unreachable exit condition ('infinite loop') vulnerability in ISOBMFF reader filter, isoffin_read.c. Function isoffin_process() can result in DoS by infinite loop. To…

  • CVE-2022-1795CriMay 18, 2022
    risk 0.00cvss 9.8epss 0.01

    Use After Free in GitHub repository gpac/gpac prior to v2.1.0-DEV.

  • CVE-2022-29340HigMay 5, 2022
    risk 0.00cvss 7.5epss 0.01

    GPAC 2.1-DEV-rev87-g053aae8-master. has a Null Pointer Dereference vulnerability in gf_isom_parse_movie_boxes_internal due to improper return value handling of GF_SKIP_BOX, which causes a Denial of Service. This vulnerability was fixed in commit 37592ad.

  • CVE-2022-29339HigMay 5, 2022
    risk 0.00cvss 7.5epss 0.01

    In GPAC 2.1-DEV-rev87-g053aae8-master, function BS_ReadByte() in utils/bitstream.c has a failed assertion, which causes a Denial of Service. This vulnerability was fixed in commit 9ea93a2.

  • CVE-2022-1441HigApr 25, 2022
    risk 0.00cvss 7.8epss 0.01

    MP4Box is a component of GPAC-2.0.0, which is a widely-used third-party package on RPM Fusion. When MP4Box tries to parse a MP4 file, it calls the function `diST_box_read()` to read from video. In this function, it allocates a buffer `str` with fixed length. However, content…

  • CVE-2022-1222MedApr 4, 2022
    risk 0.00cvss 5.5epss 0.01

    Inf loop in GitHub repository gpac/gpac prior to 2.1.0-DEV.

  • CVE-2022-1172MedMar 30, 2022
    risk 0.00cvss 5.0epss 0.01

    Null Pointer Dereference Caused Segmentation Fault in GitHub repository gpac/gpac prior to 2.1.0-DEV.

  • CVE-2022-1035MedMar 21, 2022
    risk 0.00cvss 5.5epss 0.01

    Segmentation Fault caused by MP4Box -lsr in GitHub repository gpac/gpac prior to 2.1.0-DEV.

  • CVE-2021-4043MedFeb 4, 2022
    risk 0.00cvss 5.5epss 0.05

    NULL Pointer Dereference in GitHub repository gpac/gpac prior to 1.1.0.

  • CVE-2021-40576MedJan 13, 2022
    risk 0.00cvss 5.5epss 0.01

    The binary MP4Box in Gpac 1.0.1 has a null pointer dereference vulnerability in the gf_isom_get_payt_count function in hint_track.c, which allows attackers to cause a denial of service.

  • CVE-2021-40575MedJan 13, 2022
    risk 0.00cvss 5.5epss 0.01

    The binary MP4Box in Gpac 1.0.1 has a null pointer dereference vulnerability in the mpgviddmx_process function in reframe_mpgvid.c, which allows attackers to cause a denial of service. This vulnerability is possibly due to an incomplete fix for CVE-2021-40566.

  • CVE-2021-40574HigJan 13, 2022
    risk 0.00cvss 7.8epss 0.01

    The binary MP4Box in Gpac from 0.9.0-preview to 1.0.1 has a double-free vulnerability in the gf_text_get_utf8_line function in load_text.c, which allows attackers to cause a denial of service, even code execution and escalation of privileges.

  • CVE-2021-40573MedJan 13, 2022
    risk 0.00cvss 5.5epss 0.01

    The binary MP4Box in Gpac 1.0.1 has a double-free vulnerability in the gf_list_del function in list.c, which allows attackers to cause a denial of service.

  • CVE-2021-40572MedJan 13, 2022
    risk 0.00cvss 5.5epss 0.01

    The binary MP4Box in Gpac 1.0.1 has a double-free bug in the av1dmx_finalize function in reframe_av1.c, which allows attackers to cause a denial of service.

  • CVE-2021-40571HigJan 13, 2022
    risk 0.00cvss 7.8epss 0.01

    The binary MP4Box in Gpac 1.0.1 has a double-free vulnerability in the ilst_box_read function in box_code_apple.c, which allows attackers to cause a denial of service, even code execution and escalation of privileges.

  • CVE-2021-40570HigJan 13, 2022
    risk 0.00cvss 7.8epss 0.01

    The binary MP4Box in Gpac 1.0.1 has a double-free vulnerability in the avc_compute_poc function in av_parsers.c, which allows attackers to cause a denial of service, even code execution and escalation of privileges.

  • CVE-2021-40569MedJan 13, 2022
    risk 0.00cvss 5.5epss 0.01

    The binary MP4Box in Gpac through 1.0.1 has a double-free vulnerability in the iloc_entry_del funciton in box_code_meta.c, which allows attackers to cause a denial of service.

  • CVE-2021-40568HigJan 13, 2022
    risk 0.00cvss 7.8epss 0.01

    A buffer overflow vulnerability exists in Gpac through 1.0.1 via a malformed MP4 file in the svc_parse_slice function in av_parsers.c, which allows attackers to cause a denial of service, even code execution and escalation of privileges.

  • CVE-2021-40567MedJan 13, 2022
    risk 0.00cvss 5.5epss 0.01

    Segmentation fault vulnerability exists in Gpac through 1.0.1 via the gf_odf_size_descriptor function in desc_private.c when using mp4box, which causes a denial of service.

  • CVE-2021-40566MedJan 12, 2022
    risk 0.00cvss 5.5epss 0.01

    A Segmentation fault casued by heap use after free vulnerability exists in Gpac through 1.0.1 via the mpgviddmx_process function in reframe_mpgvid.c when using mp4box, which causes a denial of service.

  • CVE-2021-40565MedJan 12, 2022
    risk 0.00cvss 5.5epss 0.01

    A Segmentation fault caused by a null pointer dereference vulnerability exists in Gpac through 1.0.1 via the gf_avc_parse_nalu function in av_parsers.c when using mp4box, which causes a denial of service.

  • CVE-2021-40564MedJan 12, 2022
    risk 0.00cvss 5.5epss 0.01

    A Segmentation fault caused by null pointer dereference vulnerability eists in Gpac through 1.0.2 via the avc_parse_slice function in av_parsers.c when using mp4box, which causes a denial of service.

  • CVE-2021-40563MedJan 12, 2022
    risk 0.00cvss 5.5epss 0.01

    A Segmentation fault exists casued by null pointer dereference exists in Gpac through 1.0.1 via the naludmx_create_avc_decoder_config function in reframe_nalu.c when using mp4box, which causes a denial of service.

  • CVE-2021-40562MedJan 12, 2022
    risk 0.00cvss 5.5epss 0.01

    A Segmentation fault caused by a floating point exception exists in Gpac through 1.0.1 using mp4box via the naludmx_enqueue_or_dispatch function in reframe_nalu.c, which causes a denial of service.

  • CVE-2020-25427MedJan 10, 2022
    risk 0.00cvss 5.5epss 0.01

    A Null pointer dereference vulnerability exits in MP4Box - GPAC version 0.8.0-rev177-g51a8ef874-master via the gf_isom_get_track_id function, which causes a denial of service.

  • CVE-2021-32268HigSep 20, 2021
    risk 0.00cvss 7.8epss 0.01

    Buffer overflow vulnerability in function gf_fprintf in os_file.c in gpac before 1.0.1 allows attackers to execute arbitrary code. The fixed version is 1.0.1.

  • CVE-2021-33365MedSep 13, 2021
    risk 0.00cvss 5.5epss 0.01

    Memory leak in the gf_isom_get_root_od function in MP4Box in GPAC 1.0.1 allows attackers to read memory via a crafted file.

  • CVE-2021-33363MedSep 13, 2021
    risk 0.00cvss 5.5epss 0.01

    Memory leak in the infe_box_read function in MP4Box in GPAC 1.0.1 allows attackers to read memory via a crafted file.

  • CVE-2021-33361MedSep 13, 2021
    risk 0.00cvss 5.5epss 0.01

    Memory leak in the afra_box_read function in MP4Box in GPAC 1.0.1 allows attackers to read memory via a crafted file.

  • CVE-2021-32139MedSep 13, 2021
    risk 0.00cvss 5.5epss 0.01

    The gf_isom_vp_config_get function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.

  • CVE-2021-32138MedSep 13, 2021
    risk 0.00cvss 5.5epss 0.01

    The DumpTrackInfo function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.

  • CVE-2021-33366MedSep 13, 2021
    risk 0.00cvss 5.5epss 0.01

    Memory leak in the gf_isom_oinf_read_entry function in MP4Box in GPAC 1.0.1 allows attackers to read memory via a crafted file.

  • CVE-2021-33364MedSep 13, 2021
    risk 0.00cvss 5.5epss 0.01

    Memory leak in the def_parent_box_new function in MP4Box in GPAC 1.0.1 allows attackers to read memory via a crafted file.

  • CVE-2021-33362HigSep 13, 2021
    risk 0.00cvss 7.8epss 0.01

    Stack buffer overflow in the hevc_parse_vps_extension function in MP4Box in GPAC 1.0.1 allows attackers to cause a denial of service or execute arbitrary code via a crafted file.

  • CVE-2021-32135MedSep 13, 2021
    risk 0.00cvss 5.5epss 0.01

    The trak_box_size function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.

  • CVE-2021-32132MedSep 13, 2021
    risk 0.00cvss 5.5epss 0.01

    The abst_box_size function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.

  • CVE-2021-32137MedSep 13, 2021
    risk 0.00cvss 5.5epss 0.01

    Heap buffer overflow in the URL_GetProtocolType function in MP4Box in GPAC 1.0.1 allows attackers to cause a denial of service or execute arbitrary code via a crafted file.

  • CVE-2021-32134MedSep 13, 2021
    risk 0.00cvss 5.5epss 0.01

    The gf_odf_desc_copy function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.

  • CVE-2021-32136HigSep 13, 2021
    risk 0.00cvss 7.8epss 0.01

    Heap buffer overflow in the print_udta function in MP4Box in GPAC 1.0.1 allows attackers to cause a denial of service or execute arbitrary code via a crafted file.

  • CVE-2021-32440MedAug 11, 2021
    risk 0.00cvss 5.5epss 0.01

    The Media_RewriteODFrame function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.

  • CVE-2021-32439HigAug 11, 2021
    risk 0.00cvss 7.8epss 0.01

    Buffer overflow in the stbl_AppendSize function in MP4Box in GPAC 1.0.1 allows attackers to cause a denial of service or execute arbitrary code via a crafted file.

  • CVE-2021-32438MedAug 11, 2021
    risk 0.00cvss 5.5epss 0.01

    The gf_media_export_filters function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.

  • CVE-2021-32437MedAug 11, 2021
    risk 0.00cvss 5.5epss 0.01

    The gf_hinter_finalize function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.

  • CVE-2020-24829MedAug 4, 2021
    risk 0.00cvss 5.5epss 0.01

    An issue was discovered in GPAC from v0.5.2 to v0.8.0, as demonstrated by MP4Box. It contains a heap-based buffer overflow in gf_m2ts_section_complete in media_tools/mpegts.c that can cause a denial of service (DOS) via a crafted MP4 file.

  • CVE-2020-19488MedJul 21, 2021
    risk 0.00cvss 5.5epss 0.01

    An issue was discovered in box_code_apple.c:119 in Gpac MP4Box 0.8.0, allows attackers to cause a Denial of Service due to an invalid read on function ilst_item_Read.

  • CVE-2020-19481MedJul 21, 2021
    risk 0.00cvss 5.5epss 0.01

    An issue was discovered in GPAC before 0.8.0, as demonstrated by MP4Box. It contains an invalid memory read in gf_m2ts_process_pmt in media_tools/mpegts.c that can cause a denial of service via a crafted MP4 file.

Page 8 of 9