VYPR

Vendor CVEs

Gpac

All CVEs

420 total · sorted by risk
  • CVE-2019-20167Dec 30, 2019
    risk 0.00cvss epss 0.01

    An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is a NULL pointer dereference in the function senc_Parse() in isomedia/box_code_drm.c.

  • CVE-2019-20168Dec 30, 2019
    risk 0.00cvss epss 0.01

    An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is a use-after-free in the function gf_isom_box_dump_ex() in isomedia/box_funcs.c.

  • CVE-2019-20169Dec 30, 2019
    risk 0.00cvss epss 0.01

    An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is a use-after-free in the function trak_Read() in isomedia/box_code_base.c.

  • CVE-2019-20170Dec 30, 2019
    risk 0.00cvss epss 0.01

    An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is an invalid pointer dereference in the function GF_IPMPX_AUTH_Delete() in odf/ipmpx_code.c.

  • CVE-2019-20171Dec 30, 2019
    risk 0.00cvss epss 0.01

    An issue was discovered in GPAC version 0.5.2 and 0.9.0-development-20191109. There are memory leaks in metx_New in isomedia/box_code_base.c and abst_Read in isomedia/box_code_adobe.c.

  • CVE-2018-21015Sep 16, 2019
    risk 0.00cvss epss 0.01

    AVC_DuplicateConfig() at isomedia/avc_ext.c in GPAC 0.7.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file. There is "cfg_new->AVCLevelIndication = cfg->AVCLevelIndication;" but cfg could be NULL.

  • CVE-2018-21016Sep 16, 2019
    risk 0.00cvss epss 0.01

    audio_sample_entry_AddBox() at isomedia/box_code_base.c in GPAC 0.7.1 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.

  • CVE-2018-21017Sep 16, 2019
    risk 0.00cvss epss 0.01

    GPAC 0.7.1 has a memory leak in dinf_Read in isomedia/box_code_base.c.

  • CVE-2019-13618Jul 16, 2019
    risk 0.00cvss epss 0.02

    In GPAC before 0.8.0, isomedia/isom_read.c in libgpac.a has a heap-based buffer over-read, as demonstrated by a crash in gf_m2ts_sync in media_tools/mpegts.c.

  • CVE-2019-12483May 30, 2019
    risk 0.00cvss epss 0.01

    An issue was discovered in GPAC 0.7.1. There is a heap-based buffer overflow in the function ReadGF_IPMPX_RemoveToolNotificationListener in odf/ipmpx_code.c in libgpac.a, as demonstrated by MP4Box.

  • CVE-2019-12482May 30, 2019
    risk 0.00cvss epss 0.02

    An issue was discovered in GPAC 0.7.1. There is a NULL pointer dereference in the function gf_isom_get_original_format_type at isomedia/drm_sample.c in libgpac.a, as demonstrated by MP4Box.

  • CVE-2019-12481May 30, 2019
    risk 0.00cvss epss 0.01

    An issue was discovered in GPAC 0.7.1. There is a NULL pointer dereference in the function GetESD at isomedia/track.c in libgpac.a, as demonstrated by MP4Box.

  • CVE-2019-11222Apr 12, 2019
    risk 0.00cvss epss 0.01

    gf_bin128_parse in utils/os_divers.c in GPAC 0.7.1 has a buffer overflow issue for the crypt feature when encountering a crafted_drm_file.xml file.

  • CVE-2019-11221Apr 12, 2019
    risk 0.00cvss epss 0.01

    GPAC 0.7.1 has a buffer overflow issue in gf_import_message() in media_import.c.

  • CVE-2018-20761Feb 6, 2019
    risk 0.00cvss epss 0.01

    GPAC version 0.7.1 and earlier has a Buffer Overflow vulnerability in the gf_sm_load_init function in scene_manager.c in libgpac_static.a.

  • CVE-2018-20763Feb 6, 2019
    risk 0.00cvss epss 0.01

    In GPAC 0.7.1 and earlier, gf_text_get_utf8_line in media_tools/text_import.c in libgpac_static.a allows an out-of-bounds write because of missing szLineConv bounds checking.

  • CVE-2018-20760Feb 6, 2019
    risk 0.00cvss epss 0.01

    In GPAC 0.7.1 and earlier, gf_text_get_utf8_line in media_tools/text_import.c in libgpac_static.a allows an out-of-bounds write because a certain -1 return value is mishandled.

  • CVE-2018-20762Feb 6, 2019
    risk 0.00cvss epss 0.01

    GPAC version 0.7.1 and earlier has a buffer overflow vulnerability in the cat_multiple_files function in applications/mp4box/fileimport.c when MP4Box is used for a local directory containing crafted filenames.

  • CVE-2018-13006CriJun 29, 2018
    risk 0.00cvss 9.8epss 0.02

    An issue was discovered in MP4Box in GPAC 0.7.1. There is a heap-based buffer over-read in the isomedia/box_dump.c function hdlr_dump.

  • CVE-2018-7752HigMar 7, 2018
    risk 0.00cvss 7.8epss 0.02

    GPAC through 0.7.1 has a Buffer Overflow in the gf_media_avc_read_sps function in media_tools/av_parsers.c, a different vulnerability than CVE-2018-1000100.

Page 9 of 9