Aurelien David

51 exploits Active since Mar 2018
CVE-2026-15185 WRITEUP LOW WRITEUP
GPAC MP4Box vobsub.c vobsub_read_idx out-of-bounds
A vulnerability was determined in GPAC 26.03-DEV. This affects the function vobsub_read_idx of the file /src/media_tools/vobsub.c of the component MP4Box. Executing a manipulation of the argument num_langs can lead to out-of-bounds read. The attack needs to be launched locally. The exploit has been publicly disclosed and may be utilized. This patch is called 532097084729a936bcdf6a27c41003f3bd7dc3ff. It is best practice to apply a patch to resolve this issue. Two different commits were applied to fix this issue.
CVSS 3.3
CVE-2026-50810 WRITEUP MEDIUM WRITEUP
GPAC < b35c61f - Denial of Service via NULL Pointer Dereference in smooth_parse_stream_index
A NULL pointer dereference in smooth_parse_stream_index() in src/media_tools/mpd.c in GPAC master HEAD before commit b35c61f104b85fbb16520ac2838d5d2ef70845b5 allows attackers to cause a denial of service
CVSS 5.5
CVE-2025-15667 WRITEUP LOW WRITEUP
GPAC MP4Box avc_ext.c gf_isom_nalu_sample_rewrite double free
A vulnerability was determined in GPAC up to 2.5-DEV. This vulnerability affects the function gf_isom_nalu_sample_rewrite of the file src/isomedia/avc_ext.c of the component MP4Box. This manipulation of the argument nalu_out_bs causes double free. It is possible to launch the attack on the local host. The exploit has been publicly disclosed and may be utilized. Patch name: f29f955f2a3b5e8e507caad3e52319f961bf37bf. To fix this issue, it is recommended to deploy a patch.
CVSS 3.3
CVE-2025-15668 WRITEUP LOW WRITEUP
GPAC MP4Box box_code_base.c sgpd_del_entry heap-based overflow
A vulnerability was identified in GPAC up to b40ce70f5. This issue affects the function sgpd_del_entry of the file src/isomedia/box_code_base.c of the component MP4Box. Such manipulation of the argument data leads to heap-based buffer overflow. Local access is required to approach this attack. The exploit is publicly available and might be used. The name of the patch is f29f955f2a3b5e8e507caad3e52319f961bf37bf. It is advisable to implement a patch to correct this issue.
CVSS 3.3
CVE-2026-14801 WRITEUP LOW WRITEUP
GPAC TeXML File load_text.c txtin_probe_duration divide by zero
A security vulnerability has been detected in GPAC 26.03-DEV-rev342-g80071f700-master. The impacted element is the function txtin_probe_duration of the file src/filters/load_text.c of the component TeXML File Handler. Such manipulation of the argument txml_timescale leads to divide by zero. An attack has to be approached locally. The name of the patch is 86a5191f2e750c767253e27ed6cfd6d547afebc2. A patch should be applied to remediate this issue.
CVSS 3.3
CVE-2026-14790 WRITEUP LOW WRITEUP
GPAC Media File write_nhml.c nhmldump_send_frame null pointer dereference
A flaw has been found in GPAC 26.02.0. This affects the function nhmldump_send_frame of the file src/filters/write_nhml.c of the component Media File Handler. Executing a manipulation can lead to null pointer dereference. The attack requires local access. The exploit has been published and may be used. This patch is called bd1d94e70e3bef364c07c5a1d94eca5c9f56e160. A patch should be applied to remediate this issue. The project explains: "I would consider most of these more as bugs than vulns but anyway they're good to fix".
CVSS 3.3
CVE-2025-55639 WRITEUP MEDIUM WRITEUP
GPAC MP4Box 2.4 - Denial of Service via Crafted MP4 File
GPAC MP4Box v2.4 was discovered to contain a NULL pointer dereference in the gf_isom_add_track_kind() function at isomedia/isom_write.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted MP4 file.
CVSS 6.5
CVE-2025-60477 WRITEUP MEDIUM WRITEUP
GPAC Project/MP4Box < 26.02.0 - Denial of Service via Crafted File in gf_filter_pid_resolve_file_template_ex
A NULL pointer dereference in the gf_filter_pid_resolve_file_template_ex function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted file.
CVSS 5.0
CVE-2025-60481 WRITEUP MEDIUM WRITEUP
GPAC Project/MP4Box < 26.02.0 - Denial of Service via Crafted AC4 File
A NULL pointer dereference in the gf_odf_ac4_cfg_dsi_v1 function (/odf/descriptors.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AC4 file.
CVSS 5.5
CVE-2025-60483 WRITEUP MEDIUM WRITEUP
GPAC Project/MP4Box < 26.02.0 - Denial of Service via Crafted AC4 File
A NULL pointer dereference in the gf_ac4_pres_b_4_back_channels_present function (/media_tools/av_parsers.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AC4 file.
CVSS 5.5
CVE-2025-60485 WRITEUP MEDIUM WRITEUP
GPAC Project/MP4Box < 26.02.0 - Denial of Service via Crafted MP4 File
A segmentation violation in the gf_isom_apple_set_tag_ex function (/isomedia/isom_write.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.
CVSS 5.5
CVE-2025-60486 WRITEUP MEDIUM WRITEUP
GPAC Project/MP4Box < 26.02.0 - Denial of Service via Heap Use-After-Free in dasher_process
A heap use-after-free in the dasher_process function (/filters/dasher.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MPEG-2 file.
CVSS 5.5
CVE-2026-9572 WRITEUP LOW WRITEUP
GPAC MP4Box media.c Media_GetSample memory leak
A security vulnerability has been detected in GPAC up to 2.4.0. Affected by this issue is the function Media_GetSample of the file src/isomedia/media.c of the component MP4Box. Such manipulation of the argument cat leads to memory leak. The attack can only be performed from a local environment. The exploit has been disclosed publicly and may be used. The name of the patch is e79c5cbe8b3fed27f4854ec229457d30c96206f1. It is best practice to apply a patch to resolve this issue.
CVSS 3.3
CVE-2026-9567 WRITEUP LOW WRITEUP
GPAC MP4Box isom_intern.c MergeFragment null pointer dereference
A security flaw has been discovered in GPAC up to 2.4.0. Affected is the function MergeFragment of the file src/isomedia/isom_intern.c of the component MP4Box. The manipulation results in null pointer dereference. The attack needs to be approached locally. The exploit has been released to the public and may be used for attacks. The patch is identified as 525bf1af642c30af04e4df5345e6d798c0a4d8a1. It is advisable to implement a patch to correct this issue.
CVSS 3.3
CVE-2026-8124 WRITEUP LOW WRITEUP
GPAC box_code_base.c sidx_box_read allocation of resources
A security vulnerability has been detected in GPAC up to 26.02.0. This affects the function sidx_box_read of the file src/isomedia/box_code_base.c. The manipulation leads to allocation of resources. The attack must be carried out locally. The exploit has been disclosed publicly and may be used. The identifier of the patch is 442e2299530138d8f874fd885c565ba98a6318ba. It is suggested to install a patch to address this issue.
CVSS 3.3
CVE-2026-39103 WRITEUP MEDIUM WRITEUP
GPAC <v391dc7f4d234988ea0bc3cc294eb725eddf8f702 - Buffer Overflow
Buffer Overflow vulnerability in GPAC before commit v391dc7f4d234988ea0bc3cc294eb725eddf8f702 allows an attacker to cause a denial of service via the src/scenegraph/svg_attributes.c, svg_parse_strings(), gf_svg_parse_attribute()
CVSS 5.5
CVE-2026-7135 WRITEUP MEDIUM WRITEUP
GPAC MP4Box box_code_base.c elng_box_read out-of-bounds
A security flaw has been discovered in GPAC up to 26.03-DEV-rev105-g8f39a1eb3-master. Affected by this vulnerability is the function elng_box_read of the file src/isomedia/box_code_base.c of the component MP4Box. Performing a manipulation of the argument elng results in out-of-bounds read. The attack needs to be approached locally. The exploit has been released to the public and may be used for attacks. The patch is named cf6ac48c972eaaee2af270adc3f36615325deb3e. The affected component should be upgraded.
CVSS 5.3
CVE-2026-33144 WRITEUP MEDIUM WRITEUP
GPAC MP4Box Heap Buffer Overflow Write in gf_xml_parse_bit_sequence_bs (NHML BS Parsing)
GPAC is an open-source multimedia framework. Prior to commit 86b0e36, a heap-based buffer overflow (write) vulnerability was discovered in GPAC MP4Box. The vulnerability exists in the gf_xml_parse_bit_sequence_bs function in utils/xml_bin_custom.c when processing a crafted NHML file containing malicious <BS> (BitSequence) elements. An attacker can exploit this by providing a specially crafted NHML file, causing an out-of-bounds write on the heap. This issue has been via commit 86b0e36.
CVSS 5.8
CVE-2026-27821 WRITEUP HIGH WRITEUP
gpac <= 26.02.0 - Stack-based Buffer Overflow in NHML File Parser
GPAC is an open-source multimedia framework. In versions up to and including 26.02.0, a stack buffer overflow occurs during NHML file parsing in `src/filters/dmx_nhml.c`. The value of the xmlHeaderEnd XML attribute is copied from att->value into szXmlHeaderEnd[1000] using strcpy() without any length validation. If the input exceeds 1000 bytes, it overwrites beyond the stack buffer boundary. Commit 9bd7137fded2db40de61a2cf3045812c8741ec52 patches the issue.
CVSS 7.8
CVE-2018-13006 WRITEUP CRITICAL WRITEUP
Debian Linux - Out-of-Bounds Read
An issue was discovered in MP4Box in GPAC 0.7.1. There is a heap-based buffer over-read in the isomedia/box_dump.c function hdlr_dump.
CVSS 9.8
CVE-2018-20760 WRITEUP HIGH WRITEUP
GPAC < 0.7.1 - Out-of-bounds Write in gf_text_get_utf8_line
In GPAC 0.7.1 and earlier, gf_text_get_utf8_line in media_tools/text_import.c in libgpac_static.a allows an out-of-bounds write because a certain -1 return value is mishandled.
CVSS 7.8
CVE-2018-20761 WRITEUP HIGH WRITEUP
GPAC < 0.7.1 - Buffer Overflow in gf_sm_load_init
GPAC version 0.7.1 and earlier has a Buffer Overflow vulnerability in the gf_sm_load_init function in scene_manager.c in libgpac_static.a.
CVSS 7.8
CVE-2018-20762 WRITEUP HIGH WRITEUP
GPAC < 0.7.1 - Buffer Overflow via Crafted Filenames in MP4Box
GPAC version 0.7.1 and earlier has a buffer overflow vulnerability in the cat_multiple_files function in applications/mp4box/fileimport.c when MP4Box is used for a local directory containing crafted filenames.
CVSS 7.8
CVE-2018-20763 WRITEUP HIGH WRITEUP
GPAC < 0.7.1 - Out-of-bounds Write in gf_text_get_utf8_line
In GPAC 0.7.1 and earlier, gf_text_get_utf8_line in media_tools/text_import.c in libgpac_static.a allows an out-of-bounds write because of missing szLineConv bounds checking.
CVSS 7.8
CVE-2018-21017 WRITEUP MEDIUM WRITEUP
GPAC 0.7.1 - Use-After-Free in dinf_Read
GPAC 0.7.1 has a memory leak in dinf_Read in isomedia/box_code_base.c.
CVSS 6.5