Exploit Database

148,525 exploits tracked across all sources.

Sort: Activity Stars
CVE-2023-46930 WRITEUP MEDIUM
GPAC 2.3-DEV-rev605-gfc9e29089-master - Memory Corruption
GPAC 2.3-DEV-rev605-gfc9e29089-master contains a SEGV in gpac/MP4Box in gf_isom_find_od_id_for_track /afltest/gpac/src/isomedia/media_odf.c:522:14.
CVSS 5.5
CVE-2023-46929 WRITEUP HIGH
GPAC 2.3-DEV-rev605-gfc9e29089-master - Denial of Service in MP4Box AVC VUI Parser
An issue discovered in GPAC 2.3-DEV-rev605-gfc9e29089-master in MP4Box in gf_avc_change_vui /afltest/gpac/src/media_tools/av_parsers.c:6872:55 allows attackers to crash the application.
CVSS 7.5
CVE-2023-46928 WRITEUP MEDIUM
GPAC 2.3-DEV-rev605-gfc9e29089-master - Memory Corruption
GPAC 2.3-DEV-rev605-gfc9e29089-master contains a SEGV in gpac/MP4Box in gf_media_change_pl /afltest/gpac/src/media_tools/isom_tools.c:3293:42.
CVSS 5.5
CVE-2023-46927 WRITEUP MEDIUM
GPAC 2.3-DEV-rev605-gfc9e29089-master - Heap-Based Buffer Overflow in gf_isom_use_compact_size
GPAC 2.3-DEV-rev605-gfc9e29089-master contains a heap-buffer-overflow in gf_isom_use_compact_size gpac/src/isomedia/isom_write.c:3403:3 in gpac/MP4Box.
CVSS 5.5
CVE-2023-46871 WRITEUP MEDIUM
GPAC < 2.3-dev-rev602-ged8424300-master - Denial of Service via Memory Leak in NewSFDouble
GPAC version 2.3-DEV-rev602-ged8424300-master in MP4Box contains a memory leak in NewSFDouble scenegraph/vrml_tools.c:300. This vulnerability may lead to a denial of service.
CVSS 5.3
CVE-2023-46427 WRITEUP CRITICAL
Gpac <2.3-DEV-rev588-g7edc40fee-master - RCE/DoS/Info Disclosure
An issue was discovered in gpac version 2.3-DEV-rev588-g7edc40fee-master, allows remote attackers to execute arbitrary code, cause a denial of service (DoS), and obtain sensitive information via null pointer deference in gf_dash_setup_period component in media_tools/dash_client.c.
CVSS 9.8
CVE-2023-46426 WRITEUP HIGH
gpac 2.3-DEV-rev588-g7edc40fee-master - Heap-based Buffer Overflow in gf_fwrite
Heap-based Buffer Overflow vulnerability in gpac version 2.3-DEV-rev588-g7edc40fee-master, allows remote attackers to execute arbitrary code and cause a denial of service (DoS) via gf_fwrite component in at utils/os_file.c.
CVSS 8.8
CVE-2023-46001 WRITEUP MEDIUM
gpac MP4Box 2.3-DEV-rev573-g201320819-master - Buffer Overflow in gf_isom_get_user_data
Buffer Overflow vulnerability in gpac MP4Box v.2.3-DEV-rev573-g201320819-master allows a local attacker to cause a denial of service via the gpac/src/isomedia/isom_read.c:2807:51 function in gf_isom_get_user_data.
CVSS 5.5
CVE-2023-42298 WRITEUP MEDIUM
GPAC < 2.2.1 - Denial of Service via Q_DecCoordOnUnitSphere Function
An issue in GPAC GPAC v.2.2.1 and before allows a local attacker to cause a denial of service via the Q_DecCoordOnUnitSphere function of file src/bifs/unquantize.c.
CVSS 5.5
CVE-2023-41000 WRITEUP MEDIUM
GPAC < 2.2.1 - Use-After-Free in gf_bifs_flush_command_list
GPAC through 2.2.1 has a use-after-free vulnerability in the function gf_bifs_flush_command_list in bifs/memory_decoder.c.
CVSS 5.5
CVE-2023-39562 WRITEUP MEDIUM
GPAC v2.3-DEV-rev449-g5948e4f70-master - Use-After-Free in gf_bs_align Function
GPAC v2.3-DEV-rev449-g5948e4f70-master was discovered to contain a heap-use-after-free via the gf_bs_align function at bitstream.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via supplying a crafted file.
CVSS 5.5
CVE-2023-37767 WRITEUP MEDIUM
GPAC v2.3-DEV-rev381-g817a848f6-master - Out-of-bounds Write in BM_ParseIndexValueReplace
GPAC v2.3-DEV-rev381-g817a848f6-master was discovered to contain a segmentation violation in the BM_ParseIndexValueReplace function at /lib/libgpac.so.
CVSS 5.5
CVE-2023-37766 WRITEUP MEDIUM
GPAC v2.3-DEV-rev381-g817a848f6-master - Out-of-bounds Write in gf_isom_remove_user_data
GPAC v2.3-DEV-rev381-g817a848f6-master was discovered to contain a segmentation violation in the gf_isom_remove_user_data function at /lib/libgpac.so.
CVSS 5.5
CVE-2023-37765 WRITEUP MEDIUM
GPAC v2.3-DEV-rev381-g817a848f6-master - Out-of-bounds Write in gf_dump_vrml_sffield
GPAC v2.3-DEV-rev381-g817a848f6-master was discovered to contain a segmentation violation in the gf_dump_vrml_sffield function at /lib/libgpac.so.
CVSS 5.5
CVE-2023-37174 WRITEUP MEDIUM
GPAC v2.3-DEV-rev381-g817a848f6-master - Out-of-bounds Write in dump_isom_scene
GPAC v2.3-DEV-rev381-g817a848f6-master was discovered to contain a segmentation violation in the dump_isom_scene function at /mp4box/filedump.c.
CVSS 5.5
CVE-2023-1452 WRITEUP MEDIUM
GPAC 2.3-DEV-rev35-gbbca86917-master - Buffer Overflow
A vulnerability was found in GPAC 2.3-DEV-rev35-gbbca86917-master. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file filters/load_text.c. The manipulation leads to buffer overflow. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The identifier VDB-223297 was assigned to this vulnerability.
CVSS 5.3
CVE-2023-1449 WRITEUP MEDIUM
GPAC 2.3-DEV-rev35-gbbca86917-master - Double Free
A vulnerability has been found in GPAC 2.3-DEV-rev35-gbbca86917-master and classified as problematic. This vulnerability affects the function gf_av1_reset_state of the file media_tools/av_parsers.c. The manipulation leads to double free. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. VDB-223294 is the identifier assigned to this vulnerability.
CVSS 5.3
CVE-2023-1448 WRITEUP MEDIUM
GPAC 2.3-DEV-rev35-gbbca86917-master - Buffer Overflow
A vulnerability, which was classified as problematic, was found in GPAC 2.3-DEV-rev35-gbbca86917-master. This affects the function gf_m2ts_process_sdt of the file media_tools/mpegts.c. The manipulation leads to heap-based buffer overflow. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The identifier VDB-223293 was assigned to this vulnerability.
CVSS 5.3
CVE-2022-47663 WRITEUP HIGH
GPAC < 2.2.0 - Buffer Overflow in h263dmx_process
GPAC MP4box 2.1-DEV-rev649-ga8f438d20 is vulnerable to buffer overflow in h263dmx_process filters/reframe_h263.c:609
CVSS 7.8
CVE-2022-47662 WRITEUP MEDIUM
GPAC MP4Box <2.1 - Memory Corruption
GPAC MP4Box 2.1-DEV-rev649-ga8f438d20 has a segment fault (/stack overflow) due to infinite recursion in Media_GetSample isomedia/media.c:662
CVSS 5.5
CVE-2022-47661 WRITEUP HIGH
GPAC < 2.2.0 - Out-of-bounds Write in gf_media_nalu_add_emulation_bytes
GPAC MP4Box 2.1-DEV-rev649-ga8f438d20 is vulnerable to Buffer Overflow via media_tools/av_parsers.c:4988 in gf_media_nalu_add_emulation_bytes
CVSS 7.8
CVE-2022-47660 WRITEUP HIGH
GPAC < 2.2.0 - Integer Overflow in isom_write.c
GPAC MP4Box 2.1-DEV-rev644-g5c4df2a67 is has an integer overflow in isomedia/isom_write.c
CVSS 7.8
CVE-2022-47659 WRITEUP HIGH
GPAC < 2.2.0 - Buffer Overflow in gf_bs_read_data
GPAC MP4box 2.1-DEV-rev644-g5c4df2a67 is vulnerable to Buffer Overflow in gf_bs_read_data
CVSS 7.8
CVE-2022-47658 WRITEUP HIGH
GPAC < 2.2.0 - Buffer Overflow in gf_hevc_read_vps_bs_internal
GPAC MP4Box 2.1-DEV-rev644-g5c4df2a67 is vulnerable to buffer overflow in function gf_hevc_read_vps_bs_internal of media_tools/av_parsers.c:8039
CVSS 7.8
CVE-2022-47657 WRITEUP HIGH
GPAC < 2.2.0 - Buffer Overflow in hevc_parse_vps_extension
GPAC MP4Box 2.1-DEV-rev644-g5c4df2a67 is vulnerable to buffer overflow in function hevc_parse_vps_extension of media_tools/av_parsers.c:7662
CVSS 7.8