Exploit Database

148,580 exploits tracked across all sources.

Sort: Activity Stars
CVE-2019-13618 WRITEUP HIGH
GPAC < 0.8.0 - Heap-Based Buffer Over-Read in isomedia/isom_read.c
In GPAC before 0.8.0, isomedia/isom_read.c in libgpac.a has a heap-based buffer over-read, as demonstrated by a crash in gf_m2ts_sync in media_tools/mpegts.c.
CVSS 7.5
CVE-2019-13618 WRITEUP HIGH
GPAC < 0.8.0 - Heap-Based Buffer Over-Read in isomedia/isom_read.c
In GPAC before 0.8.0, isomedia/isom_read.c in libgpac.a has a heap-based buffer over-read, as demonstrated by a crash in gf_m2ts_sync in media_tools/mpegts.c.
CVSS 7.5
CVE-2019-12483 WRITEUP HIGH
Debian Linux < 0.7.1 - Out-of-Bounds Write
An issue was discovered in GPAC 0.7.1. There is a heap-based buffer overflow in the function ReadGF_IPMPX_RemoveToolNotificationListener in odf/ipmpx_code.c in libgpac.a, as demonstrated by MP4Box.
CVSS 7.8
CVE-2019-12482 WRITEUP HIGH
Debian Linux < 0.7.1 - NULL Pointer Dereference
An issue was discovered in GPAC 0.7.1. There is a NULL pointer dereference in the function gf_isom_get_original_format_type at isomedia/drm_sample.c in libgpac.a, as demonstrated by MP4Box.
CVSS 7.5
CVE-2019-12481 WRITEUP MEDIUM
GPAC 0.6.1-0.7.1 - NULL Pointer Dereference in GetESD Function
An issue was discovered in GPAC 0.7.1. There is a NULL pointer dereference in the function GetESD at isomedia/track.c in libgpac.a, as demonstrated by MP4Box.
CVSS 5.5
CVE-2019-11222 WRITEUP HIGH
GPAC 0.7.1 - Out-of-bounds Write in gf_bin128_parse
gf_bin128_parse in utils/os_divers.c in GPAC 0.7.1 has a buffer overflow issue for the crypt feature when encountering a crafted_drm_file.xml file.
CVSS 7.8
CVE-2019-11222 WRITEUP HIGH
GPAC 0.7.1 - Out-of-bounds Write in gf_bin128_parse
gf_bin128_parse in utils/os_divers.c in GPAC 0.7.1 has a buffer overflow issue for the crypt feature when encountering a crafted_drm_file.xml file.
CVSS 7.8
CVE-2019-11221 WRITEUP HIGH
GPAC 0.7.1 - Out-of-bounds Write in gf_import_message
GPAC 0.7.1 has a buffer overflow issue in gf_import_message() in media_import.c.
CVSS 7.8
CVE-2018-7752 WRITEUP HIGH
GPAC < 0.7.1 - Buffer Overflow in gf_media_avc_read_sps
GPAC through 0.7.1 has a Buffer Overflow in the gf_media_avc_read_sps function in media_tools/av_parsers.c, a different vulnerability than CVE-2018-1000100.
CVSS 7.8
CVE-2018-21017 WRITEUP MEDIUM
GPAC 0.7.1 - Use-After-Free in dinf_Read
GPAC 0.7.1 has a memory leak in dinf_Read in isomedia/box_code_base.c.
CVSS 6.5
CVE-2018-21016 WRITEUP MEDIUM
GPAC 0.7.1 - Denial of Service via Crafted File in audio_sample_entry_AddBox
audio_sample_entry_AddBox() at isomedia/box_code_base.c in GPAC 0.7.1 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.
CVSS 6.5
CVE-2018-21015 WRITEUP MEDIUM
GPAC 0.7.1 - Denial of Service via NULL Pointer Dereference in AVC_DuplicateConfig
AVC_DuplicateConfig() at isomedia/avc_ext.c in GPAC 0.7.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file. There is "cfg_new->AVCLevelIndication = cfg->AVCLevelIndication;" but cfg could be NULL.
CVSS 6.5
CVE-2018-20763 WRITEUP HIGH
GPAC < 0.7.1 - Out-of-bounds Write in gf_text_get_utf8_line
In GPAC 0.7.1 and earlier, gf_text_get_utf8_line in media_tools/text_import.c in libgpac_static.a allows an out-of-bounds write because of missing szLineConv bounds checking.
CVSS 7.8
CVE-2018-20762 WRITEUP HIGH
GPAC < 0.7.1 - Buffer Overflow via Crafted Filenames in MP4Box
GPAC version 0.7.1 and earlier has a buffer overflow vulnerability in the cat_multiple_files function in applications/mp4box/fileimport.c when MP4Box is used for a local directory containing crafted filenames.
CVSS 7.8
CVE-2018-20761 WRITEUP HIGH
GPAC < 0.7.1 - Buffer Overflow in gf_sm_load_init
GPAC version 0.7.1 and earlier has a Buffer Overflow vulnerability in the gf_sm_load_init function in scene_manager.c in libgpac_static.a.
CVSS 7.8
CVE-2018-20760 WRITEUP HIGH
GPAC < 0.7.1 - Out-of-bounds Write in gf_text_get_utf8_line
In GPAC 0.7.1 and earlier, gf_text_get_utf8_line in media_tools/text_import.c in libgpac_static.a allows an out-of-bounds write because a certain -1 return value is mishandled.
CVSS 7.8
CVE-2018-13005 WRITEUP CRITICAL
Debian Linux - Out-of-Bounds Read
An issue was discovered in MP4Box in GPAC 0.7.1. The function urn_Read in isomedia/box_code_base.c has a heap-based buffer over-read.
CVSS 9.8
CVE-2018-1000100 WRITEUP HIGH
GPAC MP4Box <0.7.1 - Buffer Overflow
GPAC MP4Box version 0.7.1 and earlier contains a Buffer Overflow vulnerability in src/isomedia/avc_ext.c lines 2417 to 2420 that can result in Heap chunks being modified, this could lead to RCE. This attack appear to be exploitable via an attacker supplied MP4 file that when run by the victim may result in RCE.
CVSS 7.8
CVE-2026-4016 WRITEUP MEDIUM
GPAC 26.03-DEV - Out-of-Bounds Write in SVG Parser
A security vulnerability has been detected in GPAC 26.03-DEV. Affected by this vulnerability is the function svgin_process of the file src/filters/load_svg.c of the component SVG Parser. The manipulation leads to out-of-bounds write. Local access is required to approach this attack. The exploit has been disclosed publicly and may be used. The identifier of the patch is 7618d7206cdeb3c28961dc97ab0ecabaff0c8af2. It is suggested to install a patch to address this issue.
CVSS 5.3
CVE-2026-4016 WRITEUP MEDIUM
GPAC 26.03-DEV - Out-of-Bounds Write in SVG Parser
A security vulnerability has been detected in GPAC 26.03-DEV. Affected by this vulnerability is the function svgin_process of the file src/filters/load_svg.c of the component SVG Parser. The manipulation leads to out-of-bounds write. Local access is required to approach this attack. The exploit has been disclosed publicly and may be used. The identifier of the patch is 7618d7206cdeb3c28961dc97ab0ecabaff0c8af2. It is suggested to install a patch to address this issue.
CVSS 5.3
CVE-2026-4016 WRITEUP MEDIUM
GPAC 26.03-DEV - Out-of-Bounds Write in SVG Parser
A security vulnerability has been detected in GPAC 26.03-DEV. Affected by this vulnerability is the function svgin_process of the file src/filters/load_svg.c of the component SVG Parser. The manipulation leads to out-of-bounds write. Local access is required to approach this attack. The exploit has been disclosed publicly and may be used. The identifier of the patch is 7618d7206cdeb3c28961dc97ab0ecabaff0c8af2. It is suggested to install a patch to address this issue.
CVSS 5.3
CVE-2026-4015 WRITEUP MEDIUM
GPAC 26.03-DEV - Stack-Based Buffer Overflow in TeXML File Parser
A weakness has been identified in GPAC 26.03-DEV. Affected is the function txtin_process_texml of the file src/filters/load_text.c of the component TeXML File Parser. Executing a manipulation can lead to stack-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been made available to the public and could be used for attacks. This patch is called d29f6f1ada5cc284cdfa783b6f532c7d8bd049a5. Applying a patch is advised to resolve this issue.
CVSS 5.3
CVE-2026-4015 WRITEUP MEDIUM
GPAC 26.03-DEV - Stack-Based Buffer Overflow in TeXML File Parser
A weakness has been identified in GPAC 26.03-DEV. Affected is the function txtin_process_texml of the file src/filters/load_text.c of the component TeXML File Parser. Executing a manipulation can lead to stack-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been made available to the public and could be used for attacks. This patch is called d29f6f1ada5cc284cdfa783b6f532c7d8bd049a5. Applying a patch is advised to resolve this issue.
CVSS 5.3
CVE-2026-4015 WRITEUP MEDIUM
GPAC 26.03-DEV - Stack-Based Buffer Overflow in TeXML File Parser
A weakness has been identified in GPAC 26.03-DEV. Affected is the function txtin_process_texml of the file src/filters/load_text.c of the component TeXML File Parser. Executing a manipulation can lead to stack-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been made available to the public and could be used for attacks. This patch is called d29f6f1ada5cc284cdfa783b6f532c7d8bd049a5. Applying a patch is advised to resolve this issue.
CVSS 5.3
CVE-2026-4015 WRITEUP MEDIUM
GPAC 26.03-DEV - Stack-Based Buffer Overflow in TeXML File Parser
A weakness has been identified in GPAC 26.03-DEV. Affected is the function txtin_process_texml of the file src/filters/load_text.c of the component TeXML File Parser. Executing a manipulation can lead to stack-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been made available to the public and could be used for attacks. This patch is called d29f6f1ada5cc284cdfa783b6f532c7d8bd049a5. Applying a patch is advised to resolve this issue.
CVSS 5.3