gpac CVE Vulnerabilities & Metrics

Focus on gpac vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About gpac Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with gpac. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total gpac CVEs: 348
Earliest CVE date: 07 Mar 2018, 23:29 UTC
Latest CVE date: 23 Jan 2025, 22:15 UTC

Latest CVE reference: CVE-2024-50665

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 7

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): -100.0%
Year Variation (Calendar): -88.33%

Month Growth Rate (30-day Rolling): -100.0%
Year Growth Rate (365-day Rolling): -88.33%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical gpac CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 3.38

Max CVSS: 7.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 117
4.0-6.9 225
7.0-8.9 6
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS gpac CVEs

These are the five CVEs with the highest CVSS scores for gpac, sorted by severity first and recency.

All CVEs for gpac

CVE-2024-50665 gpac vulnerability CVSS: 0 23 Jan 2025, 22:15 UTC

gpac 2.4 contains a SEGV at src/isomedia/drm_sample.c:1562:96 in isom_cenc_get_sai_by_saiz_saio in MP4Box.

CVE-2024-50664 gpac vulnerability CVSS: 0 23 Jan 2025, 22:15 UTC

gpac 2.4 contains a heap-buffer-overflow at isomedia/sample_descs.c:1799 in gf_isom_new_mpha_description in gpac/MP4Box.

CVE-2023-4679 gpac vulnerability CVSS: 0 15 Nov 2024, 11:15 UTC

A use after free vulnerability exists in GPAC version 2.3-DEV-revrelease, specifically in the gf_filterpacket_del function in filter_core/filter.c at line 38. This vulnerability can lead to a double-free condition, which may cause the application to crash.

CVE-2024-6064 gpac vulnerability CVSS: 4.3 17 Jun 2024, 21:15 UTC

A vulnerability was found in GPAC 2.5-DEV-rev228-g11067ea92-master. It has been declared as problematic. This vulnerability affects the function xmt_node_end of the file src/scene_manager/loader_xmt.c of the component MP4Box. The manipulation leads to use after free. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The name of the patch is f4b3e4d2f91bc1749e7a924a8ab171af03a355a8/c1b9c794bad8f262c56f3cf690567980d96662f5. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-268792.

CVE-2024-6063 gpac vulnerability CVSS: 1.7 17 Jun 2024, 21:15 UTC

A vulnerability was found in GPAC 2.5-DEV-rev228-g11067ea92-master. It has been classified as problematic. This affects the function m2tsdmx_on_event of the file src/filters/dmx_m2ts.c of the component MP4Box. The manipulation leads to null pointer dereference. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The patch is named 8767ed0a77c4b02287db3723e92c2169f67c85d5. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-268791.

CVE-2024-6062 gpac vulnerability CVSS: 1.7 17 Jun 2024, 20:15 UTC

A vulnerability was found in GPAC 2.5-DEV-rev228-g11067ea92-master and classified as problematic. Affected by this issue is the function swf_svg_add_iso_sample of the file src/filters/load_text.c of the component MP4Box. The manipulation leads to null pointer dereference. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The patch is identified as 31e499d310a48bd17c8b055a0bfe0fe35887a7cd. It is recommended to apply a patch to fix this issue. VDB-268790 is the identifier assigned to this vulnerability.

CVE-2024-6061 gpac vulnerability CVSS: 1.7 17 Jun 2024, 20:15 UTC

A vulnerability has been found in GPAC 2.5-DEV-rev228-g11067ea92-master and classified as problematic. Affected by this vulnerability is the function isoffin_process of the file src/filters/isoffin_read.c of the component MP4Box. The manipulation leads to infinite loop. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The identifier of the patch is 20c0f29139a82779b86453ce7f68d0681ec7624c. It is recommended to apply a patch to fix this issue. The identifier VDB-268789 was assigned to this vulnerability.

CVE-2024-24267 gpac vulnerability CVSS: 0 05 Feb 2024, 18:15 UTC

gpac v2.2.1 was discovered to contain a memory leak via the gfio_blob variable in the gf_fileio_from_blob function.

CVE-2024-24266 gpac vulnerability CVSS: 0 05 Feb 2024, 18:15 UTC

gpac v2.2.1 was discovered to contain a Use-After-Free (UAF) vulnerability via the dasher_configure_pid function at /src/filters/dasher.c.

CVE-2024-24265 gpac vulnerability CVSS: 0 05 Feb 2024, 18:15 UTC

gpac v2.2.1 was discovered to contain a memory leak via the dst_props variable in the gf_filter_pid_merge_properties_internal function.

CVE-2024-22749 gpac vulnerability CVSS: 0 25 Jan 2024, 16:15 UTC

GPAC v2.3 was detected to contain a buffer overflow via the function gf_isom_new_generic_sample_description function in the isomedia/isom_write.c:4577

CVE-2023-50120 gpac vulnerability CVSS: 0 10 Jan 2024, 09:15 UTC

MP4Box GPAC version 2.3-DEV-rev636-gfbd7e13aa-master was discovered to contain an infinite loop in the function av1_uvlc at media_tools/av_parsers.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted MP4 file.

CVE-2024-0322 gpac vulnerability CVSS: 0 08 Jan 2024, 13:15 UTC

Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.3-DEV.

CVE-2024-0321 gpac vulnerability CVSS: 0 08 Jan 2024, 13:15 UTC

Stack-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.3-DEV.

CVE-2023-46929 gpac vulnerability CVSS: 0 03 Jan 2024, 19:15 UTC

An issue discovered in GPAC 2.3-DEV-rev605-gfc9e29089-master in MP4Box in gf_avc_change_vui /afltest/gpac/src/media_tools/av_parsers.c:6872:55 allows attackers to crash the application.

CVE-2023-46932 gpac vulnerability CVSS: 0 09 Dec 2023, 07:15 UTC

Heap Buffer Overflow vulnerability in GPAC version 2.3-DEV-rev617-g671976fcc-master, allows attackers to execute arbitrary code and cause a denial of service (DoS) via str2ulong class in src/media_tools/avilib.c in gpac/MP4Box.

CVE-2023-47465 gpac vulnerability CVSS: 0 09 Dec 2023, 06:15 UTC

An issue in GPAC v.2.2.1 and before allows a local attacker to cause a denial of service (DoS) via the ctts_box_read function of file src/isomedia/box_code_base.c.

CVE-2023-48958 gpac vulnerability CVSS: 0 07 Dec 2023, 18:15 UTC

gpac 2.3-DEV-rev617-g671976fcc-master contains memory leaks in gf_mpd_resolve_url media_tools/mpd.c:4589.

CVE-2023-46871 gpac vulnerability CVSS: 0 07 Dec 2023, 18:15 UTC

GPAC version 2.3-DEV-rev602-ged8424300-master in MP4Box contains a memory leak in NewSFDouble scenegraph/vrml_tools.c:300. This vulnerability may lead to a denial of service.

CVE-2023-48090 gpac vulnerability CVSS: 0 20 Nov 2023, 15:15 UTC

GPAC 2.3-DEV-rev617-g671976fcc-master is vulnerable to memory leaks in extract_attributes media_tools/m3u8.c:329.

CVE-2023-48039 gpac vulnerability CVSS: 0 20 Nov 2023, 15:15 UTC

GPAC 2.3-DEV-rev617-g671976fcc-master is vulnerable to memory leak in gf_mpd_parse_string media_tools/mpd.c:75.

CVE-2023-48014 gpac vulnerability CVSS: 0 15 Nov 2023, 19:15 UTC

GPAC v2.3-DEV-rev566-g50c2ab06f-master was discovered to contain a stack overflow via the hevc_parse_vps_extension function at /media_tools/av_parsers.c.

CVE-2023-48013 gpac vulnerability CVSS: 0 15 Nov 2023, 19:15 UTC

GPAC v2.3-DEV-rev566-g50c2ab06f-master was discovered to contain a double free via the gf_filterpacket_del function at /gpac/src/filter_core/filter.c.

CVE-2023-48011 gpac vulnerability CVSS: 0 15 Nov 2023, 19:15 UTC

GPAC v2.3-DEV-rev566-g50c2ab06f-master was discovered to contain a heap-use-after-free via the flush_ref_samples function at /gpac/src/isomedia/movie_fragments.c.

CVE-2023-47384 gpac vulnerability CVSS: 0 14 Nov 2023, 20:15 UTC

MP4Box GPAC v2.3-DEV-rev617-g671976fcc-master was discovered to contain a memory leak in the function gf_isom_add_chapter at /isomedia/isom_write.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted MP4 file.

CVE-2023-46001 gpac vulnerability CVSS: 0 07 Nov 2023, 22:15 UTC

Buffer Overflow vulnerability in gpac MP4Box v.2.3-DEV-rev573-g201320819-master allows a local attacker to cause a denial of service via the gpac/src/isomedia/isom_read.c:2807:51 function in gf_isom_get_user_data.

CVE-2023-5998 gpac vulnerability CVSS: 0 07 Nov 2023, 19:15 UTC

Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.3.0-DEV.

CVE-2023-46928 gpac vulnerability CVSS: 0 01 Nov 2023, 15:15 UTC

GPAC 2.3-DEV-rev605-gfc9e29089-master contains a SEGV in gpac/MP4Box in gf_media_change_pl /afltest/gpac/src/media_tools/isom_tools.c:3293:42.

CVE-2023-46927 gpac vulnerability CVSS: 0 01 Nov 2023, 15:15 UTC

GPAC 2.3-DEV-rev605-gfc9e29089-master contains a heap-buffer-overflow in gf_isom_use_compact_size gpac/src/isomedia/isom_write.c:3403:3 in gpac/MP4Box.

CVE-2023-46931 gpac vulnerability CVSS: 0 01 Nov 2023, 14:15 UTC

GPAC 2.3-DEV-rev605-gfc9e29089-master contains a heap-buffer-overflow in ffdmx_parse_side_data /afltest/gpac/src/filters/ff_dmx.c:202:14 in gpac/MP4Box.

CVE-2023-46930 gpac vulnerability CVSS: 0 01 Nov 2023, 14:15 UTC

GPAC 2.3-DEV-rev605-gfc9e29089-master contains a SEGV in gpac/MP4Box in gf_isom_find_od_id_for_track /afltest/gpac/src/isomedia/media_odf.c:522:14.

CVE-2023-5595 gpac vulnerability CVSS: 0 16 Oct 2023, 09:15 UTC

Denial of Service in GitHub repository gpac/gpac prior to 2.3.0-DEV.

CVE-2023-5586 gpac vulnerability CVSS: 0 15 Oct 2023, 01:15 UTC

NULL Pointer Dereference in GitHub repository gpac/gpac prior to 2.3.0-DEV.

CVE-2023-42298 gpac vulnerability CVSS: 0 12 Oct 2023, 04:15 UTC

An issue in GPAC GPAC v.2.2.1 and before allows a local attacker to cause a denial of service via the Q_DecCoordOnUnitSphere function of file src/bifs/unquantize.c.

CVE-2023-5520 gpac vulnerability CVSS: 0 11 Oct 2023, 12:15 UTC

Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.2.2.

CVE-2023-5377 gpac vulnerability CVSS: 0 04 Oct 2023, 10:15 UTC

Out-of-bounds Read in GitHub repository gpac/gpac prior to v2.2.2-DEV.

CVE-2023-41000 gpac vulnerability CVSS: 0 11 Sep 2023, 15:16 UTC

GPAC through 2.2.1 has a use-after-free vulnerability in the function gf_bifs_flush_command_list in bifs/memory_decoder.c.

CVE-2023-4778 gpac vulnerability CVSS: 0 05 Sep 2023, 16:15 UTC

Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.3-DEV.

CVE-2023-4758 gpac vulnerability CVSS: 0 04 Sep 2023, 16:15 UTC

Buffer Over-read in GitHub repository gpac/gpac prior to 2.3-DEV.

CVE-2023-4755 gpac vulnerability CVSS: 0 04 Sep 2023, 14:15 UTC

Use After Free in GitHub repository gpac/gpac prior to 2.3-DEV.

CVE-2023-4756 gpac vulnerability CVSS: 0 04 Sep 2023, 09:15 UTC

Stack-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.3-DEV.

CVE-2023-4754 gpac vulnerability CVSS: 0 04 Sep 2023, 09:15 UTC

Out-of-bounds Write in GitHub repository gpac/gpac prior to 2.3-DEV.

CVE-2023-4722 gpac vulnerability CVSS: 0 01 Sep 2023, 16:15 UTC

Integer Overflow or Wraparound in GitHub repository gpac/gpac prior to 2.3-DEV.

CVE-2023-4721 gpac vulnerability CVSS: 0 01 Sep 2023, 16:15 UTC

Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.3-DEV.

CVE-2023-4720 gpac vulnerability CVSS: 0 01 Sep 2023, 16:15 UTC

Floating Point Comparison with Incorrect Operator in GitHub repository gpac/gpac prior to 2.3-DEV.

CVE-2023-4683 gpac vulnerability CVSS: 0 31 Aug 2023, 16:15 UTC

NULL Pointer Dereference in GitHub repository gpac/gpac prior to 2.3-DEV.

CVE-2023-4682 gpac vulnerability CVSS: 0 31 Aug 2023, 16:15 UTC

Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.3-DEV.

CVE-2023-4681 gpac vulnerability CVSS: 0 31 Aug 2023, 16:15 UTC

NULL Pointer Dereference in GitHub repository gpac/gpac prior to 2.3-DEV.

CVE-2023-4678 gpac vulnerability CVSS: 0 31 Aug 2023, 16:15 UTC

Divide By Zero in GitHub repository gpac/gpac prior to 2.3-DEV.

CVE-2023-39562 gpac vulnerability CVSS: 0 28 Aug 2023, 19:15 UTC

GPAC v2.3-DEV-rev449-g5948e4f70-master was discovered to contain a heap-use-after-free via the gf_bs_align function at bitstream.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via supplying a crafted file.

CVE-2023-37767 gpac vulnerability CVSS: 0 11 Jul 2023, 23:15 UTC

GPAC v2.3-DEV-rev381-g817a848f6-master was discovered to contain a segmentation violation in the BM_ParseIndexValueReplace function at /lib/libgpac.so.

CVE-2023-37766 gpac vulnerability CVSS: 0 11 Jul 2023, 23:15 UTC

GPAC v2.3-DEV-rev381-g817a848f6-master was discovered to contain a segmentation violation in the gf_isom_remove_user_data function at /lib/libgpac.so.

CVE-2023-37765 gpac vulnerability CVSS: 0 11 Jul 2023, 23:15 UTC

GPAC v2.3-DEV-rev381-g817a848f6-master was discovered to contain a segmentation violation in the gf_dump_vrml_sffield function at /lib/libgpac.so.

CVE-2023-37174 gpac vulnerability CVSS: 0 11 Jul 2023, 23:15 UTC

GPAC v2.3-DEV-rev381-g817a848f6-master was discovered to contain a segmentation violation in the dump_isom_scene function at /mp4box/filedump.c.

CVE-2023-3523 gpac vulnerability CVSS: 0 06 Jul 2023, 10:15 UTC

Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.2.2.

CVE-2023-3291 gpac vulnerability CVSS: 0 16 Jun 2023, 02:15 UTC

Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.2.2.

CVE-2023-3013 gpac vulnerability CVSS: 0 31 May 2023, 14:15 UTC

Unchecked Return Value in GitHub repository gpac/gpac prior to 2.2.2.

CVE-2023-3012 gpac vulnerability CVSS: 0 31 May 2023, 14:15 UTC

NULL Pointer Dereference in GitHub repository gpac/gpac prior to 2.2.2.

CVE-2023-2840 gpac vulnerability CVSS: 0 22 May 2023, 18:15 UTC

NULL Pointer Dereference in GitHub repository gpac/gpac prior to 2.2.2.

CVE-2023-2839 gpac vulnerability CVSS: 0 22 May 2023, 18:15 UTC

Divide By Zero in GitHub repository gpac/gpac prior to 2.2.2.

CVE-2023-2838 gpac vulnerability CVSS: 0 22 May 2023, 18:15 UTC

Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.2.2.

CVE-2023-2837 gpac vulnerability CVSS: 0 22 May 2023, 18:15 UTC

Stack-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.2.2.

CVE-2023-1654 gpac vulnerability CVSS: 0 27 Mar 2023, 16:15 UTC

Denial of Service in GitHub repository gpac/gpac prior to 2.4.0.

CVE-2023-1655 gpac vulnerability CVSS: 0 27 Mar 2023, 15:15 UTC

Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.4.0.

CVE-2023-1452 gpac vulnerability CVSS: 4.3 17 Mar 2023, 07:15 UTC

A vulnerability was found in GPAC 2.3-DEV-rev35-gbbca86917-master. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file filters/load_text.c. The manipulation leads to buffer overflow. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The identifier VDB-223297 was assigned to this vulnerability.

CVE-2023-1449 gpac vulnerability CVSS: 4.3 17 Mar 2023, 07:15 UTC

A vulnerability has been found in GPAC 2.3-DEV-rev35-gbbca86917-master and classified as problematic. This vulnerability affects the function gf_av1_reset_state of the file media_tools/av_parsers.c. The manipulation leads to double free. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. VDB-223294 is the identifier assigned to this vulnerability.

CVE-2023-1448 gpac vulnerability CVSS: 4.3 17 Mar 2023, 07:15 UTC

A vulnerability, which was classified as problematic, was found in GPAC 2.3-DEV-rev35-gbbca86917-master. This affects the function gf_m2ts_process_sdt of the file media_tools/mpegts.c. The manipulation leads to heap-based buffer overflow. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The identifier VDB-223293 was assigned to this vulnerability.

CVE-2023-0866 gpac vulnerability CVSS: 0 16 Feb 2023, 20:15 UTC

Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.3.0-DEV.

CVE-2023-0841 gpac vulnerability CVSS: 7.5 15 Feb 2023, 14:15 UTC

A vulnerability, which was classified as critical, has been found in GPAC 2.3-DEV-rev40-g3602a5ded. This issue affects the function mp3_dmx_process of the file filters/reframe_mp3.c. The manipulation leads to heap-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-221087.

CVE-2023-0819 gpac vulnerability CVSS: 0 13 Feb 2023, 22:15 UTC

Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to v2.3.0-DEV.

CVE-2023-0818 gpac vulnerability CVSS: 0 13 Feb 2023, 22:15 UTC

Off-by-one Error in GitHub repository gpac/gpac prior to v2.3.0-DEV.

CVE-2023-0817 gpac vulnerability CVSS: 0 13 Feb 2023, 22:15 UTC

Buffer Over-read in GitHub repository gpac/gpac prior to v2.3.0-DEV.

CVE-2023-0770 gpac vulnerability CVSS: 0 09 Feb 2023, 22:15 UTC

Stack-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.2.

CVE-2023-0760 gpac vulnerability CVSS: 0 09 Feb 2023, 14:15 UTC

Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to V2.1.0-DEV.

CVE-2023-23145 gpac vulnerability CVSS: 0 20 Jan 2023, 19:15 UTC

GPAC version 2.2-rev0-gab012bbfb-master was discovered to contain a memory leak in lsr_read_rare_full function.

CVE-2023-23144 gpac vulnerability CVSS: 0 20 Jan 2023, 19:15 UTC

Integer overflow vulnerability in function Q_DecCoordOnUnitSphere file bifs/unquantize.c in GPAC version 2.2-rev0-gab012bbfb-master.

CVE-2023-23143 gpac vulnerability CVSS: 0 20 Jan 2023, 19:15 UTC

Buffer overflow vulnerability in function avc_parse_slice in file media_tools/av_parsers.c. GPAC version 2.3-DEV-rev1-g4669ba229-master.

CVE-2023-0358 gpac vulnerability CVSS: 0 18 Jan 2023, 02:15 UTC

Use After Free in GitHub repository gpac/gpac prior to 2.3.0-DEV.

CVE-2022-47663 gpac vulnerability CVSS: 0 05 Jan 2023, 16:15 UTC

GPAC MP4box 2.1-DEV-rev649-ga8f438d20 is vulnerable to buffer overflow in h263dmx_process filters/reframe_h263.c:609

CVE-2022-47662 gpac vulnerability CVSS: 0 05 Jan 2023, 16:15 UTC

GPAC MP4Box 2.1-DEV-rev649-ga8f438d20 has a segment fault (/stack overflow) due to infinite recursion in Media_GetSample isomedia/media.c:662

CVE-2022-47661 gpac vulnerability CVSS: 0 05 Jan 2023, 16:15 UTC

GPAC MP4Box 2.1-DEV-rev649-ga8f438d20 is vulnerable to Buffer Overflow via media_tools/av_parsers.c:4988 in gf_media_nalu_add_emulation_bytes

CVE-2022-47660 gpac vulnerability CVSS: 0 05 Jan 2023, 16:15 UTC

GPAC MP4Box 2.1-DEV-rev644-g5c4df2a67 is has an integer overflow in isomedia/isom_write.c

CVE-2022-47659 gpac vulnerability CVSS: 0 05 Jan 2023, 16:15 UTC

GPAC MP4box 2.1-DEV-rev644-g5c4df2a67 is vulnerable to Buffer Overflow in gf_bs_read_data

CVE-2022-47658 gpac vulnerability CVSS: 0 05 Jan 2023, 16:15 UTC

GPAC MP4Box 2.1-DEV-rev644-g5c4df2a67 is vulnerable to buffer overflow in function gf_hevc_read_vps_bs_internal of media_tools/av_parsers.c:8039

CVE-2022-47657 gpac vulnerability CVSS: 0 05 Jan 2023, 16:15 UTC

GPAC MP4Box 2.1-DEV-rev644-g5c4df2a67 is vulnerable to buffer overflow in function hevc_parse_vps_extension of media_tools/av_parsers.c:7662

CVE-2022-47656 gpac vulnerability CVSS: 0 05 Jan 2023, 16:15 UTC

GPAC MP4box 2.1-DEV-rev617-g85ce76efd is vulnerable to Buffer Overflow in gf_hevc_read_sps_bs_internal function of media_tools/av_parsers.c:8273

CVE-2022-47654 gpac vulnerability CVSS: 0 05 Jan 2023, 16:15 UTC

GPAC MP4box 2.1-DEV-rev593-g007bf61a0 is vulnerable to Buffer Overflow in gf_hevc_read_sps_bs_internal function of media_tools/av_parsers.c:8261

CVE-2022-47653 gpac vulnerability CVSS: 0 05 Jan 2023, 16:15 UTC

GPAC MP4box 2.1-DEV-rev593-g007bf61a0 is vulnerable to Buffer Overflow in eac3_update_channels function of media_tools/av_parsers.c:9113

CVE-2022-47095 gpac vulnerability CVSS: 0 05 Jan 2023, 15:15 UTC

GPAC MP4box 2.1-DEV-rev574-g9d5bb184b is vulnerable to Buffer overflow in hevc_parse_vps_extension function of media_tools/av_parsers.c

CVE-2022-47094 gpac vulnerability CVSS: 0 05 Jan 2023, 15:15 UTC

GPAC MP4box 2.1-DEV-rev574-g9d5bb184b is vulnerable to Null pointer dereference via filters/dmx_m2ts.c:343 in m2tsdmx_declare_pid

CVE-2022-47093 gpac vulnerability CVSS: 0 05 Jan 2023, 15:15 UTC

GPAC MP4box 2.1-DEV-rev574-g9d5bb184b is vulnerable to heap use-after-free via filters/dmx_m2ts.c:470 in m2tsdmx_declare_pid

CVE-2022-47092 gpac vulnerability CVSS: 0 05 Jan 2023, 15:15 UTC

GPAC MP4box 2.1-DEV-rev574-g9d5bb184b is contains an Integer overflow vulnerability in gf_hevc_read_sps_bs_internal function of media_tools/av_parsers.c:8316

CVE-2022-47091 gpac vulnerability CVSS: 0 05 Jan 2023, 15:15 UTC

GPAC MP4box 2.1-DEV-rev574-g9d5bb184b is vulnerable to Buffer Overflow in gf_text_process_sub function of filters/load_text.c

CVE-2022-47089 gpac vulnerability CVSS: 0 05 Jan 2023, 15:15 UTC

GPAC MP4box 2.1-DEV-rev574-g9d5bb184b is vulnerable to Buffer Overflow via gf_vvc_read_sps_bs_internal function of media_tools/av_parsers.c

CVE-2022-47088 gpac vulnerability CVSS: 0 05 Jan 2023, 15:15 UTC

GPAC MP4box 2.1-DEV-rev574-g9d5bb184b is vulnerable to Buffer Overflow.

CVE-2022-47087 gpac vulnerability CVSS: 0 05 Jan 2023, 15:15 UTC

GPAC MP4box 2.1-DEV-rev574-g9d5bb184b has a Buffer overflow in gf_vvc_read_pps_bs_internal function of media_tools/av_parsers.c

CVE-2022-47086 gpac vulnerability CVSS: 0 05 Jan 2023, 15:15 UTC

GPAC MP4Box v2.1-DEV-rev574-g9d5bb184b contains a segmentation violation via the function gf_sm_load_init_swf at scene_manager/swf_parse.c

CVE-2022-46490 gpac vulnerability CVSS: 0 05 Jan 2023, 15:15 UTC

GPAC version 2.1-DEV-rev505-gb9577e6ad-master was discovered to contain a memory leak via the afrt_box_read function at box_code_adobe.c.

CVE-2022-46489 gpac vulnerability CVSS: 0 05 Jan 2023, 15:15 UTC

GPAC version 2.1-DEV-rev505-gb9577e6ad-master was discovered to contain a memory leak via the gf_isom_box_parse_ex function at box_funcs.c.

CVE-2022-45283 gpac vulnerability CVSS: 0 06 Dec 2022, 00:15 UTC

GPAC MP4box v2.0.0 was discovered to contain a stack overflow in the smil_parse_time_list parameter at /scenegraph/svg_attributes.c.

CVE-2022-45343 gpac vulnerability CVSS: 0 29 Nov 2022, 16:15 UTC

GPAC v2.1-DEV-rev478-g696e6f868-master was discovered to contain a heap use-after-free via the Q_IsTypeOn function at /gpac/src/bifs/unquantize.c.

CVE-2022-4202 gpac vulnerability CVSS: 0 29 Nov 2022, 09:15 UTC

A vulnerability, which was classified as problematic, was found in GPAC 2.1-DEV-rev490-g68064e101-master. Affected is the function lsr_translate_coords of the file laser/lsr_dec.c. The manipulation leads to integer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The name of the patch is b3d821c4ae9ba62b3a194d9dcb5e99f17bd56908. It is recommended to apply a patch to fix this issue. VDB-214518 is the identifier assigned to this vulnerability.

CVE-2022-45204 gpac vulnerability CVSS: 0 29 Nov 2022, 04:15 UTC

GPAC v2.1-DEV-rev428-gcb8ae46c8-master was discovered to contain a memory leak via the function dimC_box_read at isomedia/box_code_3gpp.c.

CVE-2022-45202 gpac vulnerability CVSS: 0 29 Nov 2022, 04:15 UTC

GPAC v2.1-DEV-rev428-gcb8ae46c8-master was discovered to contain a stack overflow via the function dimC_box_read at isomedia/box_code_3gpp.c.

CVE-2022-3957 gpac vulnerability CVSS: 0 11 Nov 2022, 16:15 UTC

A vulnerability classified as problematic was found in GPAC. Affected by this vulnerability is the function svg_parse_preserveaspectratio of the file scenegraph/svg_attributes.c of the component SVG Parser. The manipulation leads to memory leak. The attack can be launched remotely. The name of the patch is 2191e66aa7df750e8ef01781b1930bea87b713bb. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-213463.

CVE-2022-43255 gpac vulnerability CVSS: 0 02 Nov 2022, 14:15 UTC

GPAC v2.1-DEV-rev368-gfd054169b-master was discovered to contain a memory leak via the component gf_odf_new_iod at odf/odf_code.c.

CVE-2022-43254 gpac vulnerability CVSS: 0 02 Nov 2022, 14:15 UTC

GPAC v2.1-DEV-rev368-gfd054169b-master was discovered to contain a memory leak via the component gf_list_new at utils/list.c.

CVE-2022-43045 gpac vulnerability CVSS: 0 19 Oct 2022, 14:15 UTC

GPAC 2.1-DEV-rev368-gfd054169b-master was discovered to contain a segmentation violation via the function gf_dump_vrml_sffield at /scene_manager/scene_dump.c.

CVE-2022-43044 gpac vulnerability CVSS: 0 19 Oct 2022, 14:15 UTC

GPAC 2.1-DEV-rev368-gfd054169b-master was discovered to contain a segmentation violation via the function gf_isom_get_meta_item_info at /isomedia/meta.c.

CVE-2022-43043 gpac vulnerability CVSS: 0 19 Oct 2022, 14:15 UTC

GPAC 2.1-DEV-rev368-gfd054169b-master was discovered to contain a segmentation violation via the function BD_CheckSFTimeOffset at /bifs/field_decode.c.

CVE-2022-43042 gpac vulnerability CVSS: 0 19 Oct 2022, 14:15 UTC

GPAC 2.1-DEV-rev368-gfd054169b-master was discovered to contain a heap buffer overflow via the function FixSDTPInTRAF at isomedia/isom_intern.c.

CVE-2022-43040 gpac vulnerability CVSS: 0 19 Oct 2022, 14:15 UTC

GPAC 2.1-DEV-rev368-gfd054169b-master was discovered to contain a heap buffer overflow via the function gf_isom_box_dump_start_ex at /isomedia/box_funcs.c.

CVE-2022-43039 gpac vulnerability CVSS: 0 19 Oct 2022, 14:15 UTC

GPAC 2.1-DEV-rev368-gfd054169b-master was discovered to contain a segmentation violation via the function gf_isom_meta_restore_items_ref at /isomedia/meta.c.

CVE-2022-3222 gpac vulnerability CVSS: 0 15 Sep 2022, 09:15 UTC

Uncontrolled Recursion in GitHub repository gpac/gpac prior to 2.1.0-DEV.

CVE-2022-3178 gpac vulnerability CVSS: 0 12 Sep 2022, 17:15 UTC

Buffer Over-read in GitHub repository gpac/gpac prior to 2.1.0-DEV.

CVE-2022-38530 gpac vulnerability CVSS: 0 06 Sep 2022, 23:15 UTC

GPAC v2.1-DEV-rev232-gfcaa01ebb-master was discovered to contain a stack overflow when processing ISOM_IOD.

CVE-2022-36191 gpac vulnerability CVSS: 0 17 Aug 2022, 16:15 UTC

A heap-buffer-overflow had occurred in function gf_isom_dovi_config_get of isomedia/avc_ext.c:2490, as demonstrated by MP4Box. This vulnerability was fixed in commit fef6242.

CVE-2022-36190 gpac vulnerability CVSS: 0 17 Aug 2022, 15:15 UTC

GPAC mp4box 2.1-DEV-revUNKNOWN-master has a use-after-free vulnerability in function gf_isom_dovi_config_get. This vulnerability was fixed in commit fef6242.

CVE-2022-36186 gpac vulnerability CVSS: 0 17 Aug 2022, 15:15 UTC

A Null Pointer dereference vulnerability exists in GPAC 2.1-DEV-revUNKNOWN-master via the function gf_filter_pid_set_property_full () at filter_core/filter_pid.c:5250,which causes a Denial of Service (DoS). This vulnerability was fixed in commit b43f9d1.

CVE-2022-2549 gpac vulnerability CVSS: 0 27 Jul 2022, 15:15 UTC

NULL Pointer Dereference in GitHub repository gpac/gpac prior to v2.1.0-DEV.

CVE-2022-2454 gpac vulnerability CVSS: 0 19 Jul 2022, 14:15 UTC

Integer Overflow or Wraparound in GitHub repository gpac/gpac prior to 2.1-DEV.

CVE-2022-2453 gpac vulnerability CVSS: 0 19 Jul 2022, 14:15 UTC

Use After Free in GitHub repository gpac/gpac prior to 2.1-DEV.

CVE-2021-40944 gpac vulnerability CVSS: 4.3 28 Jun 2022, 13:15 UTC

In GPAC MP4Box 1.1.0, there is a Null pointer reference in the function gf_filter_pid_get_packet function in src/filter_core/filter_pid.c:5394, as demonstrated by GPAC. This can cause a denial of service (DOS).

CVE-2021-40609 gpac vulnerability CVSS: 4.3 28 Jun 2022, 13:15 UTC

The GetHintFormat function in GPAC 1.0.1 allows attackers to cause a denial of service via a crafted file in the MP4Box command.

CVE-2021-40608 gpac vulnerability CVSS: 4.3 28 Jun 2022, 13:15 UTC

The gf_hinter_track_finalize function in GPAC 1.0.1 allows attackers to cause a denial of service via a crafted file in the MP4Box command.

CVE-2021-40607 gpac vulnerability CVSS: 4.3 28 Jun 2022, 13:15 UTC

The schm_box_size function in GPAC 1.0.1 allows attackers to cause a denial of service via a crafted file in the MP4Box command.

CVE-2021-40606 gpac vulnerability CVSS: 4.3 28 Jun 2022, 13:15 UTC

The gf_bs_write_data function in GPAC 1.0.1 allows attackers to cause a denial of service via a crafted file in the MP4Box command.

CVE-2021-40942 gpac vulnerability CVSS: 4.3 27 Jun 2022, 21:15 UTC

In GPAC MP4Box v1.1.0, there is a heap-buffer-overflow in the function filter_parse_dyn_args function in filter_core/filter.c:1454, as demonstrated by GPAC. This can cause a denial of service (DOS).

CVE-2021-41458 gpac vulnerability CVSS: 4.3 16 Jun 2022, 10:15 UTC

In GPAC MP4Box v1.1.0, there is a stack buffer overflow at src/utils/error.c:1769 which leads to a denial of service vulnerability.

CVE-2021-40592 gpac vulnerability CVSS: 4.3 08 Jun 2022, 18:15 UTC

GPAC version before commit 71460d72ec07df766dab0a4d52687529f3efcf0a (version v1.0.1 onwards) contains loop with unreachable exit condition ('infinite loop') vulnerability in ISOBMFF reader filter, isoffin_read.c. Function isoffin_process() can result in DoS by infinite loop. To exploit, the victim must open a specially crafted mp4 file.

CVE-2022-1795 gpac vulnerability CVSS: 7.5 18 May 2022, 15:15 UTC

Use After Free in GitHub repository gpac/gpac prior to v2.1.0-DEV.

CVE-2022-30976 gpac vulnerability CVSS: 4.0 18 May 2022, 11:15 UTC

GPAC 2.0.0 misuses a certain Unicode utf8_wcslen (renamed gf_utf8_wcslen) function in utils/utf.c, resulting in a heap-based buffer over-read, as demonstrated by MP4Box.

CVE-2022-29340 gpac vulnerability CVSS: 5.0 05 May 2022, 13:15 UTC

GPAC 2.1-DEV-rev87-g053aae8-master. has a Null Pointer Dereference vulnerability in gf_isom_parse_movie_boxes_internal due to improper return value handling of GF_SKIP_BOX, which causes a Denial of Service. This vulnerability was fixed in commit 37592ad.

CVE-2022-29339 gpac vulnerability CVSS: 5.0 05 May 2022, 13:15 UTC

In GPAC 2.1-DEV-rev87-g053aae8-master, function BS_ReadByte() in utils/bitstream.c has a failed assertion, which causes a Denial of Service. This vulnerability was fixed in commit 9ea93a2.

CVE-2022-1441 gpac vulnerability CVSS: 6.8 25 Apr 2022, 17:15 UTC

MP4Box is a component of GPAC-2.0.0, which is a widely-used third-party package on RPM Fusion. When MP4Box tries to parse a MP4 file, it calls the function `diST_box_read()` to read from video. In this function, it allocates a buffer `str` with fixed length. However, content read from `bs` is controllable by user, so is the length, which causes a buffer overflow.

CVE-2022-29537 gpac vulnerability CVSS: 4.3 20 Apr 2022, 23:15 UTC

gp_rtp_builder_do_hevc in ietf/rtp_pck_mpeg4.c in GPAC 2.0.0 has a heap-based buffer over-read, as demonstrated by MP4Box.

CVE-2022-27148 gpac vulnerability CVSS: 4.3 08 Apr 2022, 16:15 UTC

GPAC mp4box 1.1.0-DEV-rev1663-g881c6a94a-master is vulnerable to Integer Overflow.

CVE-2022-27147 gpac vulnerability CVSS: 4.3 08 Apr 2022, 16:15 UTC

GPAC mp4box 1.1.0-DEV-rev1727-g8be34973d-master has a use-after-free vulnerability in function gf_node_get_attribute_by_tag.

CVE-2022-27146 gpac vulnerability CVSS: 4.3 08 Apr 2022, 16:15 UTC

GPAC mp4box 1.1.0-DEV-rev1759-geb2d1e6dd-has a heap-buffer-overflow vulnerability in function gf_isom_apple_enum_tag.

CVE-2022-27145 gpac vulnerability CVSS: 4.3 08 Apr 2022, 16:15 UTC

GPAC mp4box 1.1.0-DEV-rev1727-g8be34973d-master has a stack-overflow vulnerability in function gf_isom_get_sample_for_movie_time of mp4box.

CVE-2022-1222 gpac vulnerability CVSS: 4.3 04 Apr 2022, 10:15 UTC

Inf loop in GitHub repository gpac/gpac prior to 2.1.0-DEV.

CVE-2022-1172 gpac vulnerability CVSS: 4.3 30 Mar 2022, 10:15 UTC

Null Pointer Dereference Caused Segmentation Fault in GitHub repository gpac/gpac prior to 2.1.0-DEV.

CVE-2022-1035 gpac vulnerability CVSS: 4.3 21 Mar 2022, 13:15 UTC

Segmentation Fault caused by MP4Box -lsr in GitHub repository gpac/gpac prior to 2.1.0-DEV.

CVE-2022-24578 gpac vulnerability CVSS: 6.8 14 Mar 2022, 19:15 UTC

GPAC 1.0.1 is affected by a heap-based buffer overflow in SFS_AddString () at bifs/script_dec.c.

CVE-2022-24577 gpac vulnerability CVSS: 6.8 14 Mar 2022, 15:15 UTC

GPAC 1.0.1 is affected by a NULL pointer dereference in gf_utf8_wcslen. (gf_utf8_wcslen is a renamed Unicode utf8_wcslen function.)

CVE-2022-24576 gpac vulnerability CVSS: 4.3 14 Mar 2022, 14:15 UTC

GPAC 1.0.1 is affected by Use After Free through MP4Box.

CVE-2022-24575 gpac vulnerability CVSS: 6.8 14 Mar 2022, 14:15 UTC

GPAC 1.0.1 is affected by a stack-based buffer overflow through MP4Box.

CVE-2022-24574 gpac vulnerability CVSS: 4.3 14 Mar 2022, 14:15 UTC

GPAC 1.0.1 is affected by a NULL pointer dereference in gf_dump_vrml_field.isra ().

CVE-2022-26967 gpac vulnerability CVSS: 6.8 12 Mar 2022, 22:15 UTC

GPAC 2.0 allows a heap-based buffer overflow in gf_base64_encode. It can be triggered via MP4Box.

CVE-2021-4043 gpac vulnerability CVSS: 4.3 04 Feb 2022, 23:15 UTC

NULL Pointer Dereference in GitHub repository gpac/gpac prior to 1.1.0.

CVE-2022-24249 gpac vulnerability CVSS: 4.3 04 Feb 2022, 19:15 UTC

A Null Pointer Dereference vulnerability exists in GPAC 1.1.0 via the xtra_box_write function in /box_code_base.c, which causes a Denial of Service. This vulnerability was fixed in commit 71f9871.

CVE-2021-46313 gpac vulnerability CVSS: 4.3 21 Jan 2022, 21:15 UTC

The binary MP4Box in GPAC v1.0.1 was discovered to contain a segmentation fault via the function __memmove_avx_unaligned_erms (). This vulnerability can lead to a Denial of Service (DoS).

CVE-2021-46311 gpac vulnerability CVSS: 4.3 21 Jan 2022, 21:15 UTC

A NULL pointer dereference vulnerability exists in GPAC v1.1.0 via the function gf_sg_destroy_routes () at scenegraph/vrml_route.c. This vulnerability can lead to a Denial of Service (DoS).

CVE-2021-46240 gpac vulnerability CVSS: 4.3 21 Jan 2022, 21:15 UTC

A NULL pointer dereference vulnerability exists in GPAC v1.1.0 via the function gf_dump_vrml_sffield () at scene_manager/scene_dump.c. This vulnerability can lead to a Denial of Service (DoS).

CVE-2021-46239 gpac vulnerability CVSS: 4.3 21 Jan 2022, 21:15 UTC

The binary MP4Box in GPAC v1.1.0 was discovered to contain an invalid free vulnerability via the function gf_free () at utils/alloc.c. This vulnerability can lead to a Denial of Service (DoS).

CVE-2021-46238 gpac vulnerability CVSS: 4.3 21 Jan 2022, 21:15 UTC

GPAC v1.1.0 was discovered to contain a stack overflow via the function gf_node_get_name () at scenegraph/base_scenegraph.c. This vulnerability can lead to a program crash, causing a Denial of Service (DoS).

CVE-2021-46237 gpac vulnerability CVSS: 4.3 21 Jan 2022, 21:15 UTC

An untrusted pointer dereference vulnerability exists in GPAC v1.1.0 via the function gf_node_unregister () at scenegraph/base_scenegraph.c. This vulnerability can lead to a Denial of Service (DoS).

CVE-2021-46236 gpac vulnerability CVSS: 4.3 21 Jan 2022, 21:15 UTC

A NULL pointer dereference vulnerability exists in GPAC v1.1.0 via the function gf_sg_vrml_field_pointer_del () at scenegraph/vrml_tools.c. This vulnerability can lead to a Denial of Service (DoS).

CVE-2021-46234 gpac vulnerability CVSS: 4.3 21 Jan 2022, 21:15 UTC

A NULL pointer dereference vulnerability exists in GPAC v1.1.0 via the function gf_node_unregister () at scenegraph/base_scenegraph.c. This vulnerability can lead to a Denial of Service (DoS).

CVE-2021-45767 gpac vulnerability CVSS: 4.3 14 Jan 2022, 20:15 UTC

GPAC 1.1.0 was discovered to contain an invalid memory address dereference via the function lsr_read_id(). This vulnerability can lead to a Denial of Service (DoS).

CVE-2021-45764 gpac vulnerability CVSS: 4.3 14 Jan 2022, 20:15 UTC

GPAC v1.1.0 was discovered to contain an invalid memory address dereference via the function shift_chunk_offsets.isra().

CVE-2021-45763 gpac vulnerability CVSS: 4.3 14 Jan 2022, 19:15 UTC

GPAC v1.1.0 was discovered to contain an invalid call in the function gf_node_changed(). This vulnerability can lead to a Denial of Service (DoS).

CVE-2021-45762 gpac vulnerability CVSS: 4.3 14 Jan 2022, 19:15 UTC

GPAC v1.1.0 was discovered to contain an invalid memory address dereference via the function gf_sg_vrml_mf_reset(). This vulnerability allows attackers to cause a Denial of Service (DoS).

CVE-2021-45760 gpac vulnerability CVSS: 4.3 14 Jan 2022, 00:15 UTC

GPAC v1.1.0 was discovered to contain an invalid memory address dereference via the function gf_list_last(). This vulnerability allows attackers to cause a Denial of Service (DoS).

CVE-2021-40576 gpac vulnerability CVSS: 4.3 13 Jan 2022, 19:15 UTC

The binary MP4Box in Gpac 1.0.1 has a null pointer dereference vulnerability in the gf_isom_get_payt_count function in hint_track.c, which allows attackers to cause a denial of service.

CVE-2021-40575 gpac vulnerability CVSS: 4.3 13 Jan 2022, 19:15 UTC

The binary MP4Box in Gpac 1.0.1 has a null pointer dereference vulnerability in the mpgviddmx_process function in reframe_mpgvid.c, which allows attackers to cause a denial of service. This vulnerability is possibly due to an incomplete fix for CVE-2021-40566.

CVE-2021-40574 gpac vulnerability CVSS: 6.8 13 Jan 2022, 19:15 UTC

The binary MP4Box in Gpac from 0.9.0-preview to 1.0.1 has a double-free vulnerability in the gf_text_get_utf8_line function in load_text.c, which allows attackers to cause a denial of service, even code execution and escalation of privileges.

CVE-2021-40573 gpac vulnerability CVSS: 4.3 13 Jan 2022, 19:15 UTC

The binary MP4Box in Gpac 1.0.1 has a double-free vulnerability in the gf_list_del function in list.c, which allows attackers to cause a denial of service.

CVE-2021-40572 gpac vulnerability CVSS: 4.3 13 Jan 2022, 19:15 UTC

The binary MP4Box in Gpac 1.0.1 has a double-free bug in the av1dmx_finalize function in reframe_av1.c, which allows attackers to cause a denial of service.

CVE-2021-40571 gpac vulnerability CVSS: 6.8 13 Jan 2022, 18:15 UTC

The binary MP4Box in Gpac 1.0.1 has a double-free vulnerability in the ilst_box_read function in box_code_apple.c, which allows attackers to cause a denial of service, even code execution and escalation of privileges.

CVE-2021-40570 gpac vulnerability CVSS: 6.8 13 Jan 2022, 18:15 UTC

The binary MP4Box in Gpac 1.0.1 has a double-free vulnerability in the avc_compute_poc function in av_parsers.c, which allows attackers to cause a denial of service, even code execution and escalation of privileges.

CVE-2021-40569 gpac vulnerability CVSS: 4.3 13 Jan 2022, 18:15 UTC

The binary MP4Box in Gpac through 1.0.1 has a double-free vulnerability in the iloc_entry_del funciton in box_code_meta.c, which allows attackers to cause a denial of service.

CVE-2021-40568 gpac vulnerability CVSS: 6.8 13 Jan 2022, 18:15 UTC

A buffer overflow vulnerability exists in Gpac through 1.0.1 via a malformed MP4 file in the svc_parse_slice function in av_parsers.c, which allows attackers to cause a denial of service, even code execution and escalation of privileges.

CVE-2021-40567 gpac vulnerability CVSS: 4.3 13 Jan 2022, 18:15 UTC

Segmentation fault vulnerability exists in Gpac through 1.0.1 via the gf_odf_size_descriptor function in desc_private.c when using mp4box, which causes a denial of service.

CVE-2021-40566 gpac vulnerability CVSS: 4.3 12 Jan 2022, 22:15 UTC

A Segmentation fault casued by heap use after free vulnerability exists in Gpac through 1.0.1 via the mpgviddmx_process function in reframe_mpgvid.c when using mp4box, which causes a denial of service.

CVE-2021-40565 gpac vulnerability CVSS: 4.3 12 Jan 2022, 22:15 UTC

A Segmentation fault caused by a null pointer dereference vulnerability exists in Gpac through 1.0.1 via the gf_avc_parse_nalu function in av_parsers.c when using mp4box, which causes a denial of service.

CVE-2021-40564 gpac vulnerability CVSS: 4.3 12 Jan 2022, 22:15 UTC

A Segmentation fault caused by null pointer dereference vulnerability eists in Gpac through 1.0.2 via the avc_parse_slice function in av_parsers.c when using mp4box, which causes a denial of service.

CVE-2021-40563 gpac vulnerability CVSS: 4.3 12 Jan 2022, 22:15 UTC

A Segmentation fault exists casued by null pointer dereference exists in Gpac through 1.0.1 via the naludmx_create_avc_decoder_config function in reframe_nalu.c when using mp4box, which causes a denial of service.

CVE-2021-40562 gpac vulnerability CVSS: 4.3 12 Jan 2022, 22:15 UTC

A Segmentation fault caused by a floating point exception exists in Gpac through 1.0.1 using mp4box via the naludmx_enqueue_or_dispatch function in reframe_nalu.c, which causes a denial of service.

CVE-2021-40559 gpac vulnerability CVSS: 4.3 12 Jan 2022, 21:15 UTC

A null pointer deference vulnerability exists in gpac through 1.0.1 via the naludmx_parse_nal_avc function in reframe_nalu, which allows a denail of service.

CVE-2021-36417 gpac vulnerability CVSS: 6.8 12 Jan 2022, 19:15 UTC

A heap-based buffer overflow vulnerability exists in GPAC v1.0.1 in the gf_isom_dovi_config_get function in MP4Box, which causes a denial of service or execute arbitrary code via a crafted file.

CVE-2021-36414 gpac vulnerability CVSS: 6.8 10 Jan 2022, 23:15 UTC

A heab-based buffer overflow vulnerability exists in MP4Box in GPAC 1.0.1 via media.c, which allows attackers to cause a denial of service or execute arbitrary code via a crafted file.

CVE-2021-36412 gpac vulnerability CVSS: 6.8 10 Jan 2022, 23:15 UTC

A heap-based buffer overflow vulnerability exists in MP4Box in GPAC 1.0.1 via the gp_rtp_builder_do_mpeg12_video function, which allows attackers to possibly have unspecified other impact via a crafted file in the MP4Box command,

CVE-2020-25427 gpac vulnerability CVSS: 4.3 10 Jan 2022, 22:15 UTC

A Null pointer dereference vulnerability exits in MP4Box - GPAC version 0.8.0-rev177-g51a8ef874-master via the gf_isom_get_track_id function, which causes a denial of service.

CVE-2021-46051 gpac vulnerability CVSS: 4.3 10 Jan 2022, 14:11 UTC

A Pointer Dereference Vulnerability exists in GPAC 1.0.1 via the Media_IsSelfContained function, which could cause a Denial of Service. .

CVE-2021-46049 gpac vulnerability CVSS: 4.3 10 Jan 2022, 14:11 UTC

A Pointer Dereference Vulnerability exists in GPAC 1.0.1 via the gf_fileio_check function, which could cause a Denial of Service.

CVE-2021-46047 gpac vulnerability CVSS: 4.3 10 Jan 2022, 14:11 UTC

A Pointer Dereference Vulnerability exists in GPAC 1.0.1 via the gf_hinter_finalize function.

CVE-2021-46046 gpac vulnerability CVSS: 4.3 10 Jan 2022, 14:11 UTC

A Pointer Derefernce Vulnerbility exists GPAC 1.0.1 the gf_isom_box_size function, which could cause a Denial of Service (context-dependent).

CVE-2021-46045 gpac vulnerability CVSS: 4.3 10 Jan 2022, 14:11 UTC

GPAC 1.0.1 is affected by: Abort failed. The impact is: cause a denial of service (context-dependent).

CVE-2021-46044 gpac vulnerability CVSS: 4.3 06 Jan 2022, 21:15 UTC

A Pointer Dereference Vulnerabilty exists in GPAC 1.0.1via ShiftMetaOffset.isra, which causes a Denial of Service (context-dependent).

CVE-2021-46043 gpac vulnerability CVSS: 4.3 06 Jan 2022, 21:15 UTC

A Pointer Dereference Vulnerability exits in GPAC 1.0.1 in the gf_list_count function, which causes a Denial of Service.

CVE-2021-46042 gpac vulnerability CVSS: 4.3 06 Jan 2022, 20:15 UTC

A Pointer Dereference Vulnerability exists in GPAC 1.0.1 via the _fseeko function, which causes a Denial of Service.

CVE-2021-46041 gpac vulnerability CVSS: 4.3 06 Jan 2022, 20:15 UTC

A Segmentation Fault Vulnerability exists in GPAC 1.0.1 via the co64_box_new function, which causes a Denial of Service.

CVE-2021-46040 gpac vulnerability CVSS: 4.3 06 Jan 2022, 20:15 UTC

A Pointer Dereference Vulnerabilty exists in GPAC 1.0.1 via the finplace_shift_moov_meta_offsets function, which causes a Denial of Servie (context-dependent).

CVE-2021-46039 gpac vulnerability CVSS: 4.3 06 Jan 2022, 20:15 UTC

A Pointer Dereference Vulnerabilty exists in GPAC 1.0.1 via the shift_chunk_offsets.part function, which causes a Denial of Service (context-dependent).

CVE-2021-46038 gpac vulnerability CVSS: 4.3 05 Jan 2022, 23:15 UTC

A Pointer Dereference vulnerability exists in GPAC 1.0.1 in unlink_chunk.isra, which causes a Denial of Service (context-dependent).

CVE-2021-45831 gpac vulnerability CVSS: 4.3 05 Jan 2022, 20:15 UTC

A Null Pointer Dereference vulnerability exitgs in GPAC 1.0.1 in MP4Box via __strlen_avx2, which causes a Denial of Service.

CVE-2021-45267 gpac vulnerability CVSS: 4.3 22 Dec 2021, 18:15 UTC

An invalid memory address dereference vulnerability exists in gpac 1.1.0 via the svg_node_start function, which causes a segmentation fault and application crash.

CVE-2021-45266 gpac vulnerability CVSS: 5.0 22 Dec 2021, 18:15 UTC

A null pointer dereference vulnerability exists in gpac 1.1.0 via the lsr_read_anim_values_ex function, which causes a segmentation fault and application crash.

CVE-2021-45263 gpac vulnerability CVSS: 4.3 22 Dec 2021, 18:15 UTC

An invalid free vulnerability exists in gpac 1.1.0 via the gf_svg_delete_attribute_value function, which causes a segmentation fault and application crash.

CVE-2021-45262 gpac vulnerability CVSS: 4.3 22 Dec 2021, 18:15 UTC

An invalid free vulnerability exists in gpac 1.1.0 via the gf_sg_command_del function, which causes a segmentation fault and application crash.

CVE-2021-45260 gpac vulnerability CVSS: 4.3 22 Dec 2021, 18:15 UTC

A null pointer dereference vulnerability exists in gpac 1.1.0 in the lsr_read_id.part function, which causes a segmentation fault and application crash.

CVE-2021-45259 gpac vulnerability CVSS: 4.3 22 Dec 2021, 17:15 UTC

An Invalid pointer reference vulnerability exists in gpac 1.1.0 via the gf_svg_node_del function, which causes a segmentation fault and application crash.

CVE-2021-45258 gpac vulnerability CVSS: 4.3 22 Dec 2021, 17:15 UTC

A stack overflow vulnerability exists in gpac 1.1.0 via the gf_bifs_dec_proto_list function, which causes a segmentation fault and application crash.

CVE-2021-44927 gpac vulnerability CVSS: 4.3 21 Dec 2021, 21:15 UTC

A null pointer dereference vulnerability exists in gpac 1.1.0 in the gf_sg_vrml_mf_append function, which causes a segmentation fault and application crash.

CVE-2021-44926 gpac vulnerability CVSS: 4.3 21 Dec 2021, 21:15 UTC

A null pointer dereference vulnerability exists in gpac 1.1.0-DEV in the gf_node_get_tag function, which causes a segmentation fault and application crash.

CVE-2021-44925 gpac vulnerability CVSS: 4.3 21 Dec 2021, 21:15 UTC

A null pointer dereference vulnerability exists in gpac 1.1.0 in the gf_svg_get_attribute_name function, which causes a segmentation fault and application crash.

CVE-2021-44924 gpac vulnerability CVSS: 4.3 21 Dec 2021, 21:15 UTC

An infinite loop vulnerability exists in gpac 1.1.0 in the gf_log function, which causes a Denial of Service.

CVE-2021-44923 gpac vulnerability CVSS: 4.3 21 Dec 2021, 21:15 UTC

A null pointer dereference vulnerability exists in gpac 1.1.0 in the gf_dump_vrml_dyn_field.isra function, which causes a segmentation fault and application crash.

CVE-2021-44922 gpac vulnerability CVSS: 4.3 21 Dec 2021, 21:15 UTC

A null pointer dereference vulnerability exists in gpac 1.1.0 in the BD_CheckSFTimeOffset function, which causes a segmentation fault and application crash.

CVE-2021-44921 gpac vulnerability CVSS: 4.3 21 Dec 2021, 21:15 UTC

A null pointer dereference vulnerability exists in gpac 1.1.0 in the gf_isom_parse_movie_boxes_internal function, which causes a segmentation fault and application crash.

CVE-2021-44920 gpac vulnerability CVSS: 4.3 21 Dec 2021, 21:15 UTC

An invalid memory address dereference vulnerability exists in gpac 1.1.0 in the dump_od_to_saf.isra function, which causes a segmentation fault and application crash.

CVE-2021-44919 gpac vulnerability CVSS: 4.3 21 Dec 2021, 21:15 UTC

A Null Pointer Dereference vulnerability exists in the gf_sg_vrml_mf_alloc function in gpac 1.1.0-DEV, which causes a segmentation fault and application crash.

CVE-2021-44918 gpac vulnerability CVSS: 4.3 21 Dec 2021, 21:15 UTC

A Null Pointer Dereference vulnerability exists in gpac 1.1.0 in the gf_node_get_field function, which can cause a segmentation fault and application crash.

CVE-2021-45297 gpac vulnerability CVSS: 4.3 21 Dec 2021, 19:15 UTC

An infinite loop vulnerability exists in Gpac 1.0.1 in gf_get_bit_size.

CVE-2021-45292 gpac vulnerability CVSS: 4.3 21 Dec 2021, 18:15 UTC

The gf_isom_hint_rtp_read function in GPAC 1.0.1 allows attackers to cause a denial of service (Invalid memory address dereference) via a crafted file in the MP4Box command.

CVE-2021-45291 gpac vulnerability CVSS: 4.3 21 Dec 2021, 18:15 UTC

The gf_dump_setup function in GPAC 1.0.1 allows malicoius users to cause a denial of service (Invalid memory address dereference) via a crafted file in the MP4Box command.

CVE-2021-45289 gpac vulnerability CVSS: 4.3 21 Dec 2021, 18:15 UTC

A vulnerability exists in GPAC 1.0.1 due to an omission of security-relevant Information, which could cause a Denial of Service. The program terminates with signal SIGKILL.

CVE-2021-45288 gpac vulnerability CVSS: 4.3 21 Dec 2021, 17:15 UTC

A Double Free vulnerability exists in filedump.c in GPAC 1.0.1, which could cause a Denail of Service via a crafted file in the MP4Box command.

CVE-2020-22679 gpac vulnerability CVSS: 4.3 12 Oct 2021, 21:15 UTC

Memory leak in the sgpd_parse_entry function in MP4Box in gpac 0.8.0 allows attackers to cause a denial of service (DoS) via a crafted input.

CVE-2020-22678 gpac vulnerability CVSS: 4.3 12 Oct 2021, 21:15 UTC

An issue was discovered in gpac 0.8.0. The gf_media_nalu_remove_emulation_bytes function in av_parsers.c has a heap-based buffer overflow which can lead to a denial of service (DOS) via a crafted input.

CVE-2020-22677 gpac vulnerability CVSS: 4.3 12 Oct 2021, 21:15 UTC

An issue was discovered in gpac 0.8.0. The dump_data_hex function in box_dump.c has a heap-based buffer overflow which can lead to a denial of service (DOS) via a crafted input.

CVE-2020-22675 gpac vulnerability CVSS: 4.3 12 Oct 2021, 21:15 UTC

An issue was discovered in gpac 0.8.0. The GetGhostNum function in stbl_read.c has a heap-based buffer overflow which can lead to a denial of service (DOS) via a crafted input.

CVE-2020-22674 gpac vulnerability CVSS: 4.3 12 Oct 2021, 21:15 UTC

An issue was discovered in gpac 0.8.0. An invalid memory dereference exists in the function FixTrackID located in isom_intern.c, which allows attackers to cause a denial of service (DoS) via a crafted input.

CVE-2020-22673 gpac vulnerability CVSS: 4.3 12 Oct 2021, 21:15 UTC

Memory leak in the senc_Parse function in MP4Box in gpac 0.8.0 allows attackers to cause a denial of service (DoS) via a crafted input.

CVE-2021-41459 gpac vulnerability CVSS: 5.0 01 Oct 2021, 12:15 UTC

There is a stack buffer overflow in MP4Box v1.0.1 at src/filters/dmx_nhml.c:1008 in the nhmldmx_send_sample() function szXmlFrom parameter which leads to a denial of service vulnerability.

CVE-2021-41457 gpac vulnerability CVSS: 5.0 01 Oct 2021, 12:15 UTC

There is a stack buffer overflow in MP4Box 1.1.0 at src/filters/dmx_nhml.c in nhmldmx_init_parsing which leads to a denial of service vulnerability.

CVE-2021-41456 gpac vulnerability CVSS: 5.0 01 Oct 2021, 12:15 UTC

There is a stack buffer overflow in MP4Box v1.0.1 at src/filters/dmx_nhml.c:1004 in the nhmldmx_send_sample() function szXmlTo parameter which leads to a denial of service vulnerability.

CVE-2020-23269 gpac vulnerability CVSS: 4.3 22 Sep 2021, 00:15 UTC

An issue was discovered in gpac 0.8.0. The stbl_GetSampleSize function in isomedia/stbl_read.c has a heap-based buffer overflow which can lead to a denial of service (DOS) via a crafted media file.

CVE-2020-23267 gpac vulnerability CVSS: 5.8 22 Sep 2021, 00:15 UTC

An issue was discovered in gpac 0.8.0. The gf_hinter_track_process function in isom_hinter_track_process.c has a heap-based buffer overflow which can lead to a denial of service (DOS) via a crafted media file

CVE-2020-23266 gpac vulnerability CVSS: 4.3 22 Sep 2021, 00:15 UTC

An issue was discovered in gpac 0.8.0. The OD_ReadUTF8String function in odf_code.c has a heap-based buffer overflow which can lead to a denial of service (DOS) via a crafted media file.

CVE-2021-32271 gpac vulnerability CVSS: 6.8 20 Sep 2021, 16:15 UTC

An issue was discovered in gpac through 20200801. A stack-buffer-overflow exists in the function DumpRawUIConfig located in odf_dump.c. It allows an attacker to cause code Execution.

CVE-2021-32270 gpac vulnerability CVSS: 4.3 20 Sep 2021, 16:15 UTC

An issue was discovered in gpac through 20200801. A NULL pointer dereference exists in the function vwid_box_del located in box_code_base.c. It allows an attacker to cause Denial of Service.

CVE-2021-32269 gpac vulnerability CVSS: 4.3 20 Sep 2021, 16:15 UTC

An issue was discovered in gpac through 20200801. A NULL pointer dereference exists in the function ilst_item_box_dump located in box_dump.c. It allows an attacker to cause Denial of Service.

CVE-2021-32268 gpac vulnerability CVSS: 6.8 20 Sep 2021, 16:15 UTC

Buffer overflow vulnerability in function gf_fprintf in os_file.c in gpac before 1.0.1 allows attackers to execute arbitrary code. The fixed version is 1.0.1.

CVE-2021-33365 gpac vulnerability CVSS: 4.3 13 Sep 2021, 20:15 UTC

Memory leak in the gf_isom_get_root_od function in MP4Box in GPAC 1.0.1 allows attackers to read memory via a crafted file.

CVE-2021-33363 gpac vulnerability CVSS: 4.3 13 Sep 2021, 20:15 UTC

Memory leak in the infe_box_read function in MP4Box in GPAC 1.0.1 allows attackers to read memory via a crafted file.

CVE-2021-33361 gpac vulnerability CVSS: 4.3 13 Sep 2021, 20:15 UTC

Memory leak in the afra_box_read function in MP4Box in GPAC 1.0.1 allows attackers to read memory via a crafted file.

CVE-2021-32139 gpac vulnerability CVSS: 4.3 13 Sep 2021, 20:15 UTC

The gf_isom_vp_config_get function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.

CVE-2021-32138 gpac vulnerability CVSS: 4.3 13 Sep 2021, 20:15 UTC

The DumpTrackInfo function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.

CVE-2021-33366 gpac vulnerability CVSS: 4.3 13 Sep 2021, 19:15 UTC

Memory leak in the gf_isom_oinf_read_entry function in MP4Box in GPAC 1.0.1 allows attackers to read memory via a crafted file.

CVE-2021-33364 gpac vulnerability CVSS: 4.3 13 Sep 2021, 19:15 UTC

Memory leak in the def_parent_box_new function in MP4Box in GPAC 1.0.1 allows attackers to read memory via a crafted file.

CVE-2021-33362 gpac vulnerability CVSS: 6.8 13 Sep 2021, 19:15 UTC

Stack buffer overflow in the hevc_parse_vps_extension function in MP4Box in GPAC 1.0.1 allows attackers to cause a denial of service or execute arbitrary code via a crafted file.

CVE-2021-32135 gpac vulnerability CVSS: 4.3 13 Sep 2021, 15:15 UTC

The trak_box_size function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.

CVE-2021-32132 gpac vulnerability CVSS: 4.3 13 Sep 2021, 15:15 UTC

The abst_box_size function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.

CVE-2021-32137 gpac vulnerability CVSS: 4.3 13 Sep 2021, 14:15 UTC

Heap buffer overflow in the URL_GetProtocolType function in MP4Box in GPAC 1.0.1 allows attackers to cause a denial of service or execute arbitrary code via a crafted file.

CVE-2021-32134 gpac vulnerability CVSS: 4.3 13 Sep 2021, 14:15 UTC

The gf_odf_desc_copy function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.

CVE-2021-32136 gpac vulnerability CVSS: 6.8 13 Sep 2021, 13:15 UTC

Heap buffer overflow in the print_udta function in MP4Box in GPAC 1.0.1 allows attackers to cause a denial of service or execute arbitrary code via a crafted file.

CVE-2020-19751 gpac vulnerability CVSS: 6.4 07 Sep 2021, 20:15 UTC

An issue was discovered in gpac 0.8.0. The gf_odf_del_ipmp_tool function in odf_code.c has a heap-based buffer over-read.

CVE-2020-19750 gpac vulnerability CVSS: 5.0 07 Sep 2021, 20:15 UTC

An issue was discovered in gpac 0.8.0. The strdup function in box_code_base.c has a heap-based buffer over-read.

CVE-2021-21850 gpac vulnerability CVSS: 6.8 25 Aug 2021, 19:15 UTC

An exploitable integer overflow vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an integer overflow when the library encounters an atom using the “trun” FOURCC code due to unchecked arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user to open a video to trigger this vulnerability.

CVE-2021-21849 gpac vulnerability CVSS: 6.8 25 Aug 2021, 19:15 UTC

An exploitable integer overflow vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an integer overflow when the library encounters an atom using the “tfra” FOURCC code due to unchecked arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user to open a video to trigger this vulnerability.

CVE-2021-21848 gpac vulnerability CVSS: 6.8 25 Aug 2021, 19:15 UTC

An exploitable integer overflow vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. The library will actually reuse the parser for atoms with the “stsz” FOURCC code when parsing atoms that use the “stz2” FOURCC code and can cause an integer overflow due to unchecked arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user to open a video to trigger this vulnerability.

CVE-2021-21842 gpac vulnerability CVSS: 6.8 25 Aug 2021, 19:15 UTC

An exploitable integer overflow vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an integer overflow when processing an atom using the 'ssix' FOURCC code, due to unchecked arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user to open a video to trigger this vulnerability.

CVE-2021-21841 gpac vulnerability CVSS: 6.8 25 Aug 2021, 19:15 UTC

An exploitable integer overflow vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input when reading an atom using the 'sbgp' FOURCC code can cause an integer overflow due to unchecked arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user to open a video to trigger this vulnerability.

CVE-2021-21840 gpac vulnerability CVSS: 6.8 25 Aug 2021, 19:15 UTC

An exploitable integer overflow vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input used to process an atom using the “saio” FOURCC code cause an integer overflow due to unchecked arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user to open a video to trigger this vulnerability.

CVE-2021-21836 gpac vulnerability CVSS: 6.8 25 Aug 2021, 19:15 UTC

An exploitable integer overflow vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input using the “ctts” FOURCC code can cause an integer overflow due to unchecked arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user to open a video to trigger this vulnerability.

CVE-2021-21835 gpac vulnerability CVSS: 6.8 25 Aug 2021, 19:15 UTC

An exploitable integer overflow vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input when decoding the atom associated with the “csgp” FOURCC can cause an integer overflow due to unchecked arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user to open a video to trigger this vulnerability.

CVE-2021-21834 gpac vulnerability CVSS: 6.8 25 Aug 2021, 19:15 UTC

An exploitable integer overflow vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input when decoding the atom for the “co64” FOURCC can cause an integer overflow due to unchecked arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user to open a video to trigger this vulnerability.

CVE-2021-21862 gpac vulnerability CVSS: 6.8 18 Aug 2021, 15:15 UTC

Multiple exploitable integer truncation vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an improper memory allocation resulting in a heap-based buffer overflow that causes memory corruption The implementation of the parser used for the “Xtra” FOURCC code is handled. An attacker can convince a user to open a video to trigger this vulnerability.

CVE-2021-21858 gpac vulnerability CVSS: 6.8 18 Aug 2021, 13:15 UTC

Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an integer overflow due to unchecked addition arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user to open a video to trigger this vulnerability.

CVE-2021-21857 gpac vulnerability CVSS: 6.8 18 Aug 2021, 13:15 UTC

Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an integer overflow due to unchecked addition arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user to open a video to trigger this vulnerability.

CVE-2021-21856 gpac vulnerability CVSS: 6.8 18 Aug 2021, 13:15 UTC

Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an integer overflow due to unchecked addition arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user to open a video to trigger this vulnerability.

CVE-2021-21855 gpac vulnerability CVSS: 6.8 18 Aug 2021, 13:15 UTC

Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an integer overflow due to unchecked addition arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user to open a video to trigger this vulnerability.

CVE-2021-21854 gpac vulnerability CVSS: 6.8 18 Aug 2021, 13:15 UTC

Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an integer overflow due to unchecked addition arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user to open a video to trigger this vulnerability.

CVE-2021-21853 gpac vulnerability CVSS: 6.8 18 Aug 2021, 13:15 UTC

Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an integer overflow due to unchecked addition arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user to open a video to trigger this vulnerability.

CVE-2021-21852 gpac vulnerability CVSS: 6.8 18 Aug 2021, 13:15 UTC

Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input at “stss” decoder can cause an integer overflow due to unchecked arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user to open a video to trigger this vulnerability.

CVE-2021-21851 gpac vulnerability CVSS: 6.8 18 Aug 2021, 13:15 UTC

Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input at “csgp” decoder sample group description indices can cause an integer overflow due to unchecked arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user to open a video to trigger this vulnerability.

CVE-2021-21847 gpac vulnerability CVSS: 6.8 18 Aug 2021, 13:15 UTC

Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input in “stts” decoder can cause an integer overflow due to unchecked arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user to open a video to trigger this vulnerability.

CVE-2021-21846 gpac vulnerability CVSS: 6.8 18 Aug 2021, 13:15 UTC

Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input in “stsz” decoder can cause an integer overflow due to unchecked arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user to open a video to trigger this vulnerability.

CVE-2021-21845 gpac vulnerability CVSS: 6.8 18 Aug 2021, 13:15 UTC

Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input in “stsc” decoder can cause an integer overflow due to unchecked arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user to open a video to trigger this vulnerability.

CVE-2021-21844 gpac vulnerability CVSS: 6.8 18 Aug 2021, 13:15 UTC

Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input when encountering an atom using the “stco” FOURCC code, can cause an integer overflow due to unchecked arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user to open a video to trigger this vulnerability.

CVE-2021-21843 gpac vulnerability CVSS: 6.8 18 Aug 2021, 13:15 UTC

Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an integer overflow due to unchecked arithmetic resulting in a heap-based buffer overflow that causes memory corruption. After validating the number of ranges, at [41] the library will multiply the count by the size of the GF_SubsegmentRangeInfo structure. On a 32-bit platform, this multiplication can result in an integer overflow causing the space of the array being allocated to be less than expected. An attacker can convince a user to open a video to trigger this vulnerability.

CVE-2021-21839 gpac vulnerability CVSS: 6.8 18 Aug 2021, 13:15 UTC

Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an integer overflow due to unchecked arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user to open a video to trigger this vulnerability.

CVE-2021-21838 gpac vulnerability CVSS: 6.8 18 Aug 2021, 13:15 UTC

Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an integer overflow due to unchecked arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user to open a video to trigger this vulnerability.

CVE-2021-21837 gpac vulnerability CVSS: 6.8 18 Aug 2021, 13:15 UTC

Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an integer overflow due to unchecked arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user to open a video to trigger this vulnerability.

CVE-2021-21861 gpac vulnerability CVSS: 6.8 16 Aug 2021, 20:15 UTC

An exploitable integer truncation vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. When processing the 'hdlr' FOURCC code, a specially crafted MPEG-4 input can cause an improper memory allocation resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user to open a video to trigger this vulnerability.

CVE-2021-21860 gpac vulnerability CVSS: 6.8 16 Aug 2021, 20:15 UTC

An exploitable integer truncation vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an improper memory allocation resulting in a heap-based buffer overflow that causes memory corruption. The FOURCC code, 'trik', is parsed by the function within the library. An attacker can convince a user to open a video to trigger this vulnerability.

CVE-2021-21859 gpac vulnerability CVSS: 6.8 16 Aug 2021, 20:15 UTC

An exploitable integer truncation vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. The stri_box_read function is used when processing atoms using the 'stri' FOURCC code. An attacker can convince a user to open a video to trigger this vulnerability.

CVE-2021-32440 gpac vulnerability CVSS: 4.3 11 Aug 2021, 20:15 UTC

The Media_RewriteODFrame function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.

CVE-2021-32439 gpac vulnerability CVSS: 6.8 11 Aug 2021, 20:15 UTC

Buffer overflow in the stbl_AppendSize function in MP4Box in GPAC 1.0.1 allows attackers to cause a denial of service or execute arbitrary code via a crafted file.

CVE-2021-32438 gpac vulnerability CVSS: 4.3 11 Aug 2021, 20:15 UTC

The gf_media_export_filters function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.

CVE-2021-32437 gpac vulnerability CVSS: 4.3 11 Aug 2021, 20:15 UTC

The gf_hinter_finalize function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.

CVE-2021-36584 gpac vulnerability CVSS: 4.3 05 Aug 2021, 20:15 UTC

An issue was discovered in GPAC 1.0.1. There is a heap-based buffer overflow in the function gp_rtp_builder_do_tx3g function in ietf/rtp_pck_3gpp.c, as demonstrated by MP4Box. This can cause a denial of service (DOS).

CVE-2020-24829 gpac vulnerability CVSS: 4.3 04 Aug 2021, 21:15 UTC

An issue was discovered in GPAC from v0.5.2 to v0.8.0, as demonstrated by MP4Box. It contains a heap-based buffer overflow in gf_m2ts_section_complete in media_tools/mpegts.c that can cause a denial of service (DOS) via a crafted MP4 file.

CVE-2020-22352 gpac vulnerability CVSS: 4.3 04 Aug 2021, 21:15 UTC

The gf_dash_segmenter_probe_input function in GPAC v0.8 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.

CVE-2020-19488 gpac vulnerability CVSS: 4.3 21 Jul 2021, 18:15 UTC

An issue was discovered in box_code_apple.c:119 in Gpac MP4Box 0.8.0, allows attackers to cause a Denial of Service due to an invalid read on function ilst_item_Read.

CVE-2020-19481 gpac vulnerability CVSS: 4.3 21 Jul 2021, 18:15 UTC

An issue was discovered in GPAC before 0.8.0, as demonstrated by MP4Box. It contains an invalid memory read in gf_m2ts_process_pmt in media_tools/mpegts.c that can cause a denial of service via a crafted MP4 file.

CVE-2020-23932 gpac vulnerability CVSS: 4.3 21 Apr 2021, 18:15 UTC

An issue was discovered in gpac before 1.0.1. A NULL pointer dereference exists in the function dump_isom_sdp located in filedump.c. It allows an attacker to cause Denial of Service.

CVE-2020-23931 gpac vulnerability CVSS: 5.8 21 Apr 2021, 18:15 UTC

An issue was discovered in gpac before 1.0.1. The abst_box_read function in box_code_adobe.c has a heap-based buffer over-read.

CVE-2020-23930 gpac vulnerability CVSS: 4.3 21 Apr 2021, 18:15 UTC

An issue was discovered in gpac through 20200801. A NULL pointer dereference exists in the function nhmldump_send_header located in write_nhml.c. It allows an attacker to cause Denial of Service.

CVE-2020-23928 gpac vulnerability CVSS: 5.8 21 Apr 2021, 18:15 UTC

An issue was discovered in gpac before 1.0.1. The abst_box_read function in box_code_adobe.c has a heap-based buffer over-read.

CVE-2020-35982 gpac vulnerability CVSS: 6.8 21 Apr 2021, 16:15 UTC

An issue was discovered in GPAC version 0.8.0 and 1.0.1. There is an invalid pointer dereference in the function gf_hinter_track_finalize() in media_tools/isom_hinter.c.

CVE-2020-35981 gpac vulnerability CVSS: 6.8 21 Apr 2021, 16:15 UTC

An issue was discovered in GPAC version 0.8.0 and 1.0.1. There is an invalid pointer dereference in the function SetupWriters() in isomedia/isom_store.c.

CVE-2020-35980 gpac vulnerability CVSS: 6.8 21 Apr 2021, 16:15 UTC

An issue was discovered in GPAC version 0.8.0 and 1.0.1. There is a use-after-free in the function gf_isom_box_del() in isomedia/box_funcs.c.

CVE-2020-35979 gpac vulnerability CVSS: 6.8 21 Apr 2021, 16:15 UTC

An issue was discovered in GPAC version 0.8.0 and 1.0.1. There is heap-based buffer overflow in the function gp_rtp_builder_do_avc() in ietf/rtp_pck_mpeg4.c.

CVE-2021-30199 gpac vulnerability CVSS: 4.3 19 Apr 2021, 20:15 UTC

In filters/reframe_latm.c in GPAC 1.0.1 there is a Null Pointer Dereference, when gf_filter_pck_get_data is called. The first arg pck may be null with a crafted mp4 file,which results in a crash.

CVE-2021-30022 gpac vulnerability CVSS: 4.3 19 Apr 2021, 20:15 UTC

There is a integer overflow in media_tools/av_parsers.c in the gf_avc_read_pps_bs_internal in GPAC from 0.5.2 to 1.0.1. pps_id may be a negative number, so it will not return. However, avc->pps only has 255 unit, so there is an overflow, which results a crash.

CVE-2021-30020 gpac vulnerability CVSS: 4.3 19 Apr 2021, 20:15 UTC

In the function gf_hevc_read_pps_bs_internal function in media_tools/av_parsers.c in GPAC 1.0.1 there is a loop, which with crafted file, pps->num_tile_columns may be larger than sizeof(pps->column_width), which results in a heap overflow in the loop.

CVE-2021-30019 gpac vulnerability CVSS: 4.3 19 Apr 2021, 20:15 UTC

In the adts_dmx_process function in filters/reframe_adts.c in GPAC 1.0.1, a crafted file may cause ctx->hdr.frame_size to be smaller than ctx->hdr.hdr_size, resulting in size to be a negative number and a heap overflow in the memcpy.

CVE-2021-30015 gpac vulnerability CVSS: 4.3 19 Apr 2021, 20:15 UTC

There is a Null Pointer Dereference in function filter_core/filter_pck.c:gf_filter_pck_new_alloc_internal in GPAC 1.0.1. The pid comes from function av1dmx_parse_flush_sample, the ctx.opid maybe NULL. The result is a crash in gf_filter_pck_new_alloc_internal.

CVE-2021-30014 gpac vulnerability CVSS: 4.3 19 Apr 2021, 20:15 UTC

There is a integer overflow in media_tools/av_parsers.c in the hevc_parse_slice_segment function in GPAC from v0.9.0-preview to 1.0.1 which results in a crash.

CVE-2021-29279 gpac vulnerability CVSS: 6.8 19 Apr 2021, 20:15 UTC

There is a integer overflow in function filter_core/filter_props.c:gf_props_assign_value in GPAC 1.0.1. In which, the arg const GF_PropertyValue *value,maybe value->value.data.size is a negative number. In result, memcpy in gf_props_assign_value failed.

CVE-2021-31262 gpac vulnerability CVSS: 4.3 19 Apr 2021, 19:15 UTC

The AV1_DuplicateConfig function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.

CVE-2021-31261 gpac vulnerability CVSS: 4.3 19 Apr 2021, 19:15 UTC

The gf_hinter_track_new function in GPAC 1.0.1 allows attackers to read memory via a crafted file in the MP4Box command.

CVE-2021-31260 gpac vulnerability CVSS: 4.3 19 Apr 2021, 19:15 UTC

The MergeTrack function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.

CVE-2021-31259 gpac vulnerability CVSS: 4.3 19 Apr 2021, 19:15 UTC

The gf_isom_cenc_get_default_info_internal function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.

CVE-2021-31258 gpac vulnerability CVSS: 4.3 19 Apr 2021, 19:15 UTC

The gf_isom_set_extraction_slc function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.

CVE-2021-31257 gpac vulnerability CVSS: 4.3 19 Apr 2021, 19:15 UTC

The HintFile function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.

CVE-2021-31256 gpac vulnerability CVSS: 4.3 19 Apr 2021, 19:15 UTC

Memory leak in the stbl_GetSampleInfos function in MP4Box in GPAC 1.0.1 allows attackers to read memory via a crafted file.

CVE-2021-31255 gpac vulnerability CVSS: 6.8 19 Apr 2021, 19:15 UTC

Buffer overflow in the abst_box_read function in MP4Box in GPAC 1.0.1 allows attackers to cause a denial of service or execute arbitrary code via a crafted file.

CVE-2021-31254 gpac vulnerability CVSS: 6.8 19 Apr 2021, 19:15 UTC

Buffer overflow in the tenc_box_read function in MP4Box in GPAC 1.0.1 allows attackers to cause a denial of service or execute arbitrary code via a crafted file, related invalid IV sizes.

CVE-2021-28300 gpac vulnerability CVSS: 7.5 14 Apr 2021, 14:15 UTC

NULL Pointer Dereference in the "isomedia/track.c" module's "MergeTrack()" function of GPAC v0.5.2 allows attackers to execute arbitrary code or cause a Denial-of-Service (DoS) by uploading a malicious MP4 file.

CVE-2020-11558 gpac vulnerability CVSS: 7.5 05 Apr 2020, 20:15 UTC

An issue was discovered in libgpac.a in GPAC 0.8.0, as demonstrated by MP4Box. audio_sample_entry_Read in isomedia/box_code_base.c does not properly decide when to make gf_isom_box_del calls. This leads to various use-after-free outcomes involving mdia_Read, gf_isom_delete_movie, and gf_isom_parse_movie_boxes.

CVE-2019-20632 gpac vulnerability CVSS: 4.3 24 Mar 2020, 19:15 UTC

An issue was discovered in libgpac.a in GPAC before 0.8.0, as demonstrated by MP4Box. It contains an invalid pointer dereference in gf_odf_delete_descriptor in odf/desc_private.c that can cause a denial of service via a crafted MP4 file.

CVE-2019-20631 gpac vulnerability CVSS: 4.3 24 Mar 2020, 19:15 UTC

An issue was discovered in libgpac.a in GPAC before 0.8.0, as demonstrated by MP4Box. It contains an invalid pointer dereference in gf_list_count in utils/list.c that can cause a denial of service via a crafted MP4 file.

CVE-2019-20630 gpac vulnerability CVSS: 4.3 24 Mar 2020, 19:15 UTC

An issue was discovered in libgpac.a in GPAC before 0.8.0, as demonstrated by MP4Box. It contains a heap-based buffer over-read in BS_ReadByte (called from gf_bs_read_bit) in utils/bitstream.c that can cause a denial of service via a crafted MP4 file.

CVE-2019-20629 gpac vulnerability CVSS: 4.3 24 Mar 2020, 19:15 UTC

An issue was discovered in libgpac.a in GPAC before 0.8.0, as demonstrated by MP4Box. It contains a heap-based buffer over-read in gf_m2ts_process_pmt in media_tools/mpegts.c that can cause a denial of service via a crafted MP4 file.

CVE-2019-20628 gpac vulnerability CVSS: 4.3 24 Mar 2020, 19:15 UTC

An issue was discovered in libgpac.a in GPAC before 0.8.0, as demonstrated by MP4Box. It contains a Use-After-Free vulnerability in gf_m2ts_process_pmt in media_tools/mpegts.c that can cause a denial of service via a crafted MP4 file.

CVE-2020-6631 gpac vulnerability CVSS: 4.3 09 Jan 2020, 02:15 UTC

An issue was discovered in GPAC version 0.8.0. There is a NULL pointer dereference in the function gf_m2ts_stream_process_pmt() in media_tools/m2ts_mux.c.

CVE-2020-6630 gpac vulnerability CVSS: 4.3 09 Jan 2020, 02:15 UTC

An issue was discovered in GPAC version 0.8.0. There is a NULL pointer dereference in the function gf_isom_get_media_data_size() in isomedia/isom_read.c.

CVE-2019-20208 gpac vulnerability CVSS: 4.3 02 Jan 2020, 14:16 UTC

dimC_Read in isomedia/box_code_3gpp.c in GPAC from 0.5.2 to 0.8.0 has a stack-based buffer overflow.

CVE-2019-20171 gpac vulnerability CVSS: 4.3 31 Dec 2019, 00:15 UTC

An issue was discovered in GPAC version 0.5.2 and 0.9.0-development-20191109. There are memory leaks in metx_New in isomedia/box_code_base.c and abst_Read in isomedia/box_code_adobe.c.

CVE-2019-20170 gpac vulnerability CVSS: 4.3 31 Dec 2019, 00:15 UTC

An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is an invalid pointer dereference in the function GF_IPMPX_AUTH_Delete() in odf/ipmpx_code.c.

CVE-2019-20169 gpac vulnerability CVSS: 4.3 31 Dec 2019, 00:15 UTC

An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is a use-after-free in the function trak_Read() in isomedia/box_code_base.c.

CVE-2019-20168 gpac vulnerability CVSS: 4.3 31 Dec 2019, 00:15 UTC

An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is a use-after-free in the function gf_isom_box_dump_ex() in isomedia/box_funcs.c.

CVE-2019-20167 gpac vulnerability CVSS: 4.3 31 Dec 2019, 00:15 UTC

An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is a NULL pointer dereference in the function senc_Parse() in isomedia/box_code_drm.c.

CVE-2019-20166 gpac vulnerability CVSS: 4.3 31 Dec 2019, 00:15 UTC

An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is a NULL pointer dereference in the function gf_isom_dump() in isomedia/box_dump.c.

CVE-2019-20165 gpac vulnerability CVSS: 4.3 31 Dec 2019, 00:15 UTC

An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is a NULL pointer dereference in the function ilst_item_Read() in isomedia/box_code_apple.c.

CVE-2019-20164 gpac vulnerability CVSS: 4.3 31 Dec 2019, 00:15 UTC

An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is a NULL pointer dereference in the function gf_isom_box_del() in isomedia/box_funcs.c.

CVE-2019-20163 gpac vulnerability CVSS: 4.3 31 Dec 2019, 00:15 UTC

An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is a NULL pointer dereference in the function gf_odf_avc_cfg_write_bs() in odf/descriptors.c.

CVE-2019-20162 gpac vulnerability CVSS: 4.3 31 Dec 2019, 00:15 UTC

An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is heap-based buffer overflow in the function gf_isom_box_parse_ex() in isomedia/box_funcs.c.

CVE-2019-20161 gpac vulnerability CVSS: 4.3 31 Dec 2019, 00:15 UTC

An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is heap-based buffer overflow in the function ReadGF_IPMPX_WatermarkingInit() in odf/ipmpx_code.c.

CVE-2019-20160 gpac vulnerability CVSS: 4.3 31 Dec 2019, 00:15 UTC

An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is a stack-based buffer overflow in the function av1_parse_tile_group() in media_tools/av_parsers.c.

CVE-2019-20159 gpac vulnerability CVSS: 4.3 31 Dec 2019, 00:15 UTC

An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is a memory leak in dinf_New() in isomedia/box_code_base.c.

CVE-2018-21017 gpac vulnerability CVSS: 4.3 16 Sep 2019, 13:15 UTC

GPAC 0.7.1 has a memory leak in dinf_Read in isomedia/box_code_base.c.

CVE-2018-21016 gpac vulnerability CVSS: 4.3 16 Sep 2019, 13:15 UTC

audio_sample_entry_AddBox() at isomedia/box_code_base.c in GPAC 0.7.1 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.

CVE-2018-21015 gpac vulnerability CVSS: 4.3 16 Sep 2019, 13:15 UTC

AVC_DuplicateConfig() at isomedia/avc_ext.c in GPAC 0.7.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file. There is "cfg_new->AVCLevelIndication = cfg->AVCLevelIndication;" but cfg could be NULL.

CVE-2019-13618 gpac vulnerability CVSS: 5.0 16 Jul 2019, 17:15 UTC

In GPAC before 0.8.0, isomedia/isom_read.c in libgpac.a has a heap-based buffer over-read, as demonstrated by a crash in gf_m2ts_sync in media_tools/mpegts.c.

CVE-2019-12483 gpac vulnerability CVSS: 6.8 30 May 2019, 23:29 UTC

An issue was discovered in GPAC 0.7.1. There is a heap-based buffer overflow in the function ReadGF_IPMPX_RemoveToolNotificationListener in odf/ipmpx_code.c in libgpac.a, as demonstrated by MP4Box.

CVE-2019-12482 gpac vulnerability CVSS: 5.0 30 May 2019, 23:29 UTC

An issue was discovered in GPAC 0.7.1. There is a NULL pointer dereference in the function gf_isom_get_original_format_type at isomedia/drm_sample.c in libgpac.a, as demonstrated by MP4Box.

CVE-2019-12481 gpac vulnerability CVSS: 4.3 30 May 2019, 23:29 UTC

An issue was discovered in GPAC 0.7.1. There is a NULL pointer dereference in the function GetESD at isomedia/track.c in libgpac.a, as demonstrated by MP4Box.

CVE-2019-11222 gpac vulnerability CVSS: 6.8 15 Apr 2019, 12:31 UTC

gf_bin128_parse in utils/os_divers.c in GPAC 0.7.1 has a buffer overflow issue for the crypt feature when encountering a crafted_drm_file.xml file.

CVE-2019-11221 gpac vulnerability CVSS: 6.8 15 Apr 2019, 12:31 UTC

GPAC 0.7.1 has a buffer overflow issue in gf_import_message() in media_import.c.

CVE-2018-20760 gpac vulnerability CVSS: 6.8 06 Feb 2019, 23:29 UTC

In GPAC 0.7.1 and earlier, gf_text_get_utf8_line in media_tools/text_import.c in libgpac_static.a allows an out-of-bounds write because a certain -1 return value is mishandled.

CVE-2018-13006 gpac vulnerability CVSS: 7.5 29 Jun 2018, 14:29 UTC

An issue was discovered in MP4Box in GPAC 0.7.1. There is a heap-based buffer over-read in the isomedia/box_dump.c function hdlr_dump.

CVE-2018-13005 gpac vulnerability CVSS: 7.5 29 Jun 2018, 14:29 UTC

An issue was discovered in MP4Box in GPAC 0.7.1. The function urn_Read in isomedia/box_code_base.c has a heap-based buffer over-read.

CVE-2018-7752 gpac vulnerability CVSS: 6.8 07 Mar 2018, 23:29 UTC

GPAC through 0.7.1 has a Buffer Overflow in the gf_media_avc_read_sps function in media_tools/av_parsers.c, a different vulnerability than CVE-2018-1000100.