Writeup Exploits

60,504 exploits tracked across all sources.

Sort: Activity Stars
CVE-2021-40573 WRITEUP MEDIUM
gpac 1.0.1 - Denial of Service via Double Free in gf_list_del
The binary MP4Box in Gpac 1.0.1 has a double-free vulnerability in the gf_list_del function in list.c, which allows attackers to cause a denial of service.
CVSS 5.5
CVE-2021-40572 WRITEUP MEDIUM
GPAC MP4Box - Denial of Service via Double Free in av1dmx_finalize
The binary MP4Box in Gpac 1.0.1 has a double-free bug in the av1dmx_finalize function in reframe_av1.c, which allows attackers to cause a denial of service.
CVSS 5.5
CVE-2021-40571 WRITEUP HIGH
gpac 1.0.1 - Use-After-Free in ilst_box_read
The binary MP4Box in Gpac 1.0.1 has a double-free vulnerability in the ilst_box_read function in box_code_apple.c, which allows attackers to cause a denial of service, even code execution and escalation of privileges.
CVSS 7.8
CVE-2021-40570 WRITEUP HIGH
GPAC MP4Box - Double Free in avc_compute_poc Function
The binary MP4Box in Gpac 1.0.1 has a double-free vulnerability in the avc_compute_poc function in av_parsers.c, which allows attackers to cause a denial of service, even code execution and escalation of privileges.
CVSS 7.8
CVE-2021-40569 WRITEUP MEDIUM
gpac < 1.0.1 - Denial of Service via Double Free in iloc_entry_del
The binary MP4Box in Gpac through 1.0.1 has a double-free vulnerability in the iloc_entry_del funciton in box_code_meta.c, which allows attackers to cause a denial of service.
CVSS 5.5
CVE-2021-40568 WRITEUP HIGH
gpac < 1.0.1 - Buffer Overflow in svc_parse_slice via Malformed MP4 File
A buffer overflow vulnerability exists in Gpac through 1.0.1 via a malformed MP4 file in the svc_parse_slice function in av_parsers.c, which allows attackers to cause a denial of service, even code execution and escalation of privileges.
CVSS 7.8
CVE-2021-40567 WRITEUP MEDIUM
gpac < 1.0.1 - Denial of Service via gf_odf_size_descriptor in desc_private.c
Segmentation fault vulnerability exists in Gpac through 1.0.1 via the gf_odf_size_descriptor function in desc_private.c when using mp4box, which causes a denial of service.
CVSS 5.5
CVE-2021-40566 WRITEUP MEDIUM
gpac < 1.0.1 - Use-After-Free in mpgviddmx_process Function
A Segmentation fault casued by heap use after free vulnerability exists in Gpac through 1.0.1 via the mpgviddmx_process function in reframe_mpgvid.c when using mp4box, which causes a denial of service.
CVSS 5.5
CVE-2021-40565 WRITEUP MEDIUM
gpac < 1.0.1 - Denial of Service via Null Pointer Dereference in gf_avc_parse_nalu
A Segmentation fault caused by a null pointer dereference vulnerability exists in Gpac through 1.0.1 via the gf_avc_parse_nalu function in av_parsers.c when using mp4box, which causes a denial of service.
CVSS 5.5
CVE-2021-40564 WRITEUP MEDIUM
gpac < 1.0.2 - Denial of Service via avc_parse_slice Null Pointer Dereference
A Segmentation fault caused by null pointer dereference vulnerability eists in Gpac through 1.0.2 via the avc_parse_slice function in av_parsers.c when using mp4box, which causes a denial of service.
CVSS 5.5
CVE-2021-40563 WRITEUP MEDIUM
gpac <= 1.0.1 - Denial of Service via naludmx_create_avc_decoder_config Null Pointer Dereference
A Segmentation fault exists casued by null pointer dereference exists in Gpac through 1.0.1 via the naludmx_create_avc_decoder_config function in reframe_nalu.c when using mp4box, which causes a denial of service.
CVSS 5.5
CVE-2021-40562 WRITEUP MEDIUM
Gpac < 1.0.1 - Denial of Service via naludmx_enqueue_or_dispatch Function
A Segmentation fault caused by a floating point exception exists in Gpac through 1.0.1 using mp4box via the naludmx_enqueue_or_dispatch function in reframe_nalu.c, which causes a denial of service.
CVSS 5.5
CVE-2021-40559 WRITEUP MEDIUM
gpac <= 1.0.1 - Denial of Service via naludmx_parse_nal_avc Function
A null pointer deference vulnerability exists in gpac through 1.0.1 via the naludmx_parse_nal_avc function in reframe_nalu, which allows a denail of service.
CVSS 5.5
CVE-2021-36584 WRITEUP MEDIUM
GPAC 1.0.1 - Heap-Based Buffer Overflow in gp_rtp_builder_do_tx3g
An issue was discovered in GPAC 1.0.1. There is a heap-based buffer overflow in the function gp_rtp_builder_do_tx3g function in ietf/rtp_pck_3gpp.c, as demonstrated by MP4Box. This can cause a denial of service (DOS).
CVSS 5.5
CVE-2021-36417 WRITEUP HIGH
GPAC 1.0.1 - Heap-Based Buffer Overflow in gf_isom_dovi_config_get
A heap-based buffer overflow vulnerability exists in GPAC v1.0.1 in the gf_isom_dovi_config_get function in MP4Box, which causes a denial of service or execute arbitrary code via a crafted file.
CVSS 7.8
CVE-2021-36414 WRITEUP HIGH
GPAC 1.0.1 - Heap-Based Buffer Overflow in MP4Box via Crafted File
A heab-based buffer overflow vulnerability exists in MP4Box in GPAC 1.0.1 via media.c, which allows attackers to cause a denial of service or execute arbitrary code via a crafted file.
CVSS 7.8
CVE-2021-36412 WRITEUP HIGH
GPAC 1.0.1 - Heap-Based Buffer Overflow in MP4Box via gp_rtp_builder_do_mpeg12_video
A heap-based buffer overflow vulnerability exists in MP4Box in GPAC 1.0.1 via the gp_rtp_builder_do_mpeg12_video function, which allows attackers to possibly have unspecified other impact via a crafted file in the MP4Box command,
CVSS 7.8
CVE-2021-33366 WRITEUP MEDIUM
GPAC - Memory Leak in gf_isom_oinf_read_entry
Memory leak in the gf_isom_oinf_read_entry function in MP4Box in GPAC 1.0.1 allows attackers to read memory via a crafted file.
CVSS 5.5
CVE-2021-33365 WRITEUP MEDIUM
GPAC - Memory Leak in gf_isom_get_root_od Function
Memory leak in the gf_isom_get_root_od function in MP4Box in GPAC 1.0.1 allows attackers to read memory via a crafted file.
CVSS 5.5
CVE-2021-33364 WRITEUP MEDIUM
GPAC - Memory Leak in def_parent_box_new Function
Memory leak in the def_parent_box_new function in MP4Box in GPAC 1.0.1 allows attackers to read memory via a crafted file.
CVSS 5.5
CVE-2021-33363 WRITEUP MEDIUM
GPAC 1.0.1 - Memory Leak in infe_box_read Function
Memory leak in the infe_box_read function in MP4Box in GPAC 1.0.1 allows attackers to read memory via a crafted file.
CVSS 5.5
CVE-2021-33362 WRITEUP HIGH
GPAC 1.0.1 - Stack Buffer Overflow in hevc_parse_vps_extension
Stack buffer overflow in the hevc_parse_vps_extension function in MP4Box in GPAC 1.0.1 allows attackers to cause a denial of service or execute arbitrary code via a crafted file.
CVSS 7.8
CVE-2021-33361 WRITEUP MEDIUM
GPAC - Memory Leak in afra_box_read Function
Memory leak in the afra_box_read function in MP4Box in GPAC 1.0.1 allows attackers to read memory via a crafted file.
CVSS 5.5
CVE-2021-32440 WRITEUP MEDIUM
GPAC 1.0.1 - Denial of Service via Media_RewriteODFrame NULL Pointer Dereference
The Media_RewriteODFrame function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.
CVSS 5.5
CVE-2021-32439 WRITEUP HIGH
GPAC 1.0.1 - Buffer Overflow in stbl_AppendSize Function
Buffer overflow in the stbl_AppendSize function in MP4Box in GPAC 1.0.1 allows attackers to cause a denial of service or execute arbitrary code via a crafted file.
CVSS 7.8