Exploit Database
148,525 exploits tracked across all sources.
GPAC 2.3-DEV-rev605-gfc9e29089-master - Memory Corruption
GPAC 2.3-DEV-rev605-gfc9e29089-master contains a SEGV in gpac/MP4Box in gf_isom_find_od_id_for_track /afltest/gpac/src/isomedia/media_odf.c:522:14.
CVSS 5.5
GPAC 2.3-DEV-rev605-gfc9e29089-master - Denial of Service in MP4Box AVC VUI Parser
An issue discovered in GPAC 2.3-DEV-rev605-gfc9e29089-master in MP4Box in gf_avc_change_vui /afltest/gpac/src/media_tools/av_parsers.c:6872:55 allows attackers to crash the application.
CVSS 7.5
GPAC 2.3-DEV-rev605-gfc9e29089-master - Memory Corruption
GPAC 2.3-DEV-rev605-gfc9e29089-master contains a SEGV in gpac/MP4Box in gf_media_change_pl /afltest/gpac/src/media_tools/isom_tools.c:3293:42.
CVSS 5.5
GPAC 2.3-DEV-rev605-gfc9e29089-master - Heap-Based Buffer Overflow in gf_isom_use_compact_size
GPAC 2.3-DEV-rev605-gfc9e29089-master contains a heap-buffer-overflow in gf_isom_use_compact_size gpac/src/isomedia/isom_write.c:3403:3 in gpac/MP4Box.
CVSS 5.5
GPAC < 2.3-dev-rev602-ged8424300-master - Denial of Service via Memory Leak in NewSFDouble
GPAC version 2.3-DEV-rev602-ged8424300-master in MP4Box contains a memory leak in NewSFDouble scenegraph/vrml_tools.c:300. This vulnerability may lead to a denial of service.
CVSS 5.3
Gpac <2.3-DEV-rev588-g7edc40fee-master - RCE/DoS/Info Disclosure
An issue was discovered in gpac version 2.3-DEV-rev588-g7edc40fee-master, allows remote attackers to execute arbitrary code, cause a denial of service (DoS), and obtain sensitive information via null pointer deference in gf_dash_setup_period component in media_tools/dash_client.c.
CVSS 9.8
gpac 2.3-DEV-rev588-g7edc40fee-master - Heap-based Buffer Overflow in gf_fwrite
Heap-based Buffer Overflow vulnerability in gpac version 2.3-DEV-rev588-g7edc40fee-master, allows remote attackers to execute arbitrary code and cause a denial of service (DoS) via gf_fwrite component in at utils/os_file.c.
CVSS 8.8
gpac MP4Box 2.3-DEV-rev573-g201320819-master - Buffer Overflow in gf_isom_get_user_data
Buffer Overflow vulnerability in gpac MP4Box v.2.3-DEV-rev573-g201320819-master allows a local attacker to cause a denial of service via the gpac/src/isomedia/isom_read.c:2807:51 function in gf_isom_get_user_data.
CVSS 5.5
GPAC < 2.2.1 - Denial of Service via Q_DecCoordOnUnitSphere Function
An issue in GPAC GPAC v.2.2.1 and before allows a local attacker to cause a denial of service via the Q_DecCoordOnUnitSphere function of file src/bifs/unquantize.c.
CVSS 5.5
GPAC < 2.2.1 - Use-After-Free in gf_bifs_flush_command_list
GPAC through 2.2.1 has a use-after-free vulnerability in the function gf_bifs_flush_command_list in bifs/memory_decoder.c.
CVSS 5.5
GPAC v2.3-DEV-rev449-g5948e4f70-master - Use-After-Free in gf_bs_align Function
GPAC v2.3-DEV-rev449-g5948e4f70-master was discovered to contain a heap-use-after-free via the gf_bs_align function at bitstream.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via supplying a crafted file.
CVSS 5.5
GPAC v2.3-DEV-rev381-g817a848f6-master - Out-of-bounds Write in BM_ParseIndexValueReplace
GPAC v2.3-DEV-rev381-g817a848f6-master was discovered to contain a segmentation violation in the BM_ParseIndexValueReplace function at /lib/libgpac.so.
CVSS 5.5
GPAC v2.3-DEV-rev381-g817a848f6-master - Out-of-bounds Write in gf_isom_remove_user_data
GPAC v2.3-DEV-rev381-g817a848f6-master was discovered to contain a segmentation violation in the gf_isom_remove_user_data function at /lib/libgpac.so.
CVSS 5.5
GPAC v2.3-DEV-rev381-g817a848f6-master - Out-of-bounds Write in gf_dump_vrml_sffield
GPAC v2.3-DEV-rev381-g817a848f6-master was discovered to contain a segmentation violation in the gf_dump_vrml_sffield function at /lib/libgpac.so.
CVSS 5.5
GPAC v2.3-DEV-rev381-g817a848f6-master - Out-of-bounds Write in dump_isom_scene
GPAC v2.3-DEV-rev381-g817a848f6-master was discovered to contain a segmentation violation in the dump_isom_scene function at /mp4box/filedump.c.
CVSS 5.5
GPAC 2.3-DEV-rev35-gbbca86917-master - Buffer Overflow
A vulnerability was found in GPAC 2.3-DEV-rev35-gbbca86917-master. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file filters/load_text.c. The manipulation leads to buffer overflow. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The identifier VDB-223297 was assigned to this vulnerability.
CVSS 5.3
GPAC 2.3-DEV-rev35-gbbca86917-master - Double Free
A vulnerability has been found in GPAC 2.3-DEV-rev35-gbbca86917-master and classified as problematic. This vulnerability affects the function gf_av1_reset_state of the file media_tools/av_parsers.c. The manipulation leads to double free. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. VDB-223294 is the identifier assigned to this vulnerability.
CVSS 5.3
GPAC 2.3-DEV-rev35-gbbca86917-master - Buffer Overflow
A vulnerability, which was classified as problematic, was found in GPAC 2.3-DEV-rev35-gbbca86917-master. This affects the function gf_m2ts_process_sdt of the file media_tools/mpegts.c. The manipulation leads to heap-based buffer overflow. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The identifier VDB-223293 was assigned to this vulnerability.
CVSS 5.3
GPAC < 2.2.0 - Buffer Overflow in h263dmx_process
GPAC MP4box 2.1-DEV-rev649-ga8f438d20 is vulnerable to buffer overflow in h263dmx_process filters/reframe_h263.c:609
CVSS 7.8
GPAC MP4Box <2.1 - Memory Corruption
GPAC MP4Box 2.1-DEV-rev649-ga8f438d20 has a segment fault (/stack overflow) due to infinite recursion in Media_GetSample isomedia/media.c:662
CVSS 5.5
GPAC < 2.2.0 - Out-of-bounds Write in gf_media_nalu_add_emulation_bytes
GPAC MP4Box 2.1-DEV-rev649-ga8f438d20 is vulnerable to Buffer Overflow via media_tools/av_parsers.c:4988 in gf_media_nalu_add_emulation_bytes
CVSS 7.8
GPAC < 2.2.0 - Integer Overflow in isom_write.c
GPAC MP4Box 2.1-DEV-rev644-g5c4df2a67 is has an integer overflow in isomedia/isom_write.c
CVSS 7.8
GPAC < 2.2.0 - Buffer Overflow in gf_bs_read_data
GPAC MP4box 2.1-DEV-rev644-g5c4df2a67 is vulnerable to Buffer Overflow in gf_bs_read_data
CVSS 7.8
GPAC < 2.2.0 - Buffer Overflow in gf_hevc_read_vps_bs_internal
GPAC MP4Box 2.1-DEV-rev644-g5c4df2a67 is vulnerable to buffer overflow in function gf_hevc_read_vps_bs_internal of media_tools/av_parsers.c:8039
CVSS 7.8
GPAC < 2.2.0 - Buffer Overflow in hevc_parse_vps_extension
GPAC MP4Box 2.1-DEV-rev644-g5c4df2a67 is vulnerable to buffer overflow in function hevc_parse_vps_extension of media_tools/av_parsers.c:7662
CVSS 7.8
By Source