Writeup Exploits

60,504 exploits tracked across all sources.

Sort: Activity Stars
CVE-2019-20168 WRITEUP MEDIUM
GPAC 0.8.0 and 0.9.0-development-20191109 - Use-After-Free in gf_isom_box_dump_ex
An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is a use-after-free in the function gf_isom_box_dump_ex() in isomedia/box_funcs.c.
CVSS 5.5
CVE-2019-20167 WRITEUP MEDIUM
GPAC 0.8.0 and 0.9.0-development-20191109 - NULL Pointer Dereference in senc_Parse
An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is a NULL pointer dereference in the function senc_Parse() in isomedia/box_code_drm.c.
CVSS 5.5
CVE-2019-20166 WRITEUP MEDIUM
GPAC 0.8.0 and 0.9.0-development-20191109 - NULL Pointer Dereference in gf_isom_dump
An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is a NULL pointer dereference in the function gf_isom_dump() in isomedia/box_dump.c.
CVSS 5.5
CVE-2019-20165 WRITEUP MEDIUM
GPAC 0.8.0 and 0.9.0-development-20191109 - NULL Pointer Dereference in ilst_item_Read
An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is a NULL pointer dereference in the function ilst_item_Read() in isomedia/box_code_apple.c.
CVSS 5.5
CVE-2019-20164 WRITEUP MEDIUM
GPAC 0.8.0 and 0.9.0-development-20191109 - NULL Pointer Dereference in gf_isom_box_del()
An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is a NULL pointer dereference in the function gf_isom_box_del() in isomedia/box_funcs.c.
CVSS 5.5
CVE-2019-20163 WRITEUP MEDIUM
GPAC 0.8.0 and 0.9.0-development-20191109 - NULL Pointer Dereference in gf_odf_avc_cfg_write_bs()
An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is a NULL pointer dereference in the function gf_odf_avc_cfg_write_bs() in odf/descriptors.c.
CVSS 5.5
CVE-2019-20162 WRITEUP MEDIUM
GPAC 0.8.0 and 0.9.0-development-20191109 - Heap-Based Buffer Overflow in gf_isom_box_parse_ex
An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is heap-based buffer overflow in the function gf_isom_box_parse_ex() in isomedia/box_funcs.c.
CVSS 5.5
CVE-2019-20161 WRITEUP MEDIUM
GPAC 0.8.0 and 0.9.0-development-20191109 - Heap-Based Buffer Overflow in ReadGF_IPMPX_WatermarkingInit
An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is heap-based buffer overflow in the function ReadGF_IPMPX_WatermarkingInit() in odf/ipmpx_code.c.
CVSS 5.5
CVE-2019-20160 WRITEUP MEDIUM
GPAC 0.8.0 and 0.9.0-development-20191109 - Stack-Based Buffer Overflow in av1_parse_tile_group
An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is a stack-based buffer overflow in the function av1_parse_tile_group() in media_tools/av_parsers.c.
CVSS 5.5
CVE-2019-20159 WRITEUP MEDIUM
GPAC 0.8.0 and 0.9.0-development-20191109 - Memory Leak in dinf_New()
An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is a memory leak in dinf_New() in isomedia/box_code_base.c.
CVSS 5.5
CVE-2019-13618 WRITEUP HIGH
GPAC < 0.8.0 - Heap-Based Buffer Over-Read in isomedia/isom_read.c
In GPAC before 0.8.0, isomedia/isom_read.c in libgpac.a has a heap-based buffer over-read, as demonstrated by a crash in gf_m2ts_sync in media_tools/mpegts.c.
CVSS 7.5
CVE-2019-13618 WRITEUP HIGH
GPAC < 0.8.0 - Heap-Based Buffer Over-Read in isomedia/isom_read.c
In GPAC before 0.8.0, isomedia/isom_read.c in libgpac.a has a heap-based buffer over-read, as demonstrated by a crash in gf_m2ts_sync in media_tools/mpegts.c.
CVSS 7.5
CVE-2019-12483 WRITEUP HIGH
Debian Linux < 0.7.1 - Out-of-Bounds Write
An issue was discovered in GPAC 0.7.1. There is a heap-based buffer overflow in the function ReadGF_IPMPX_RemoveToolNotificationListener in odf/ipmpx_code.c in libgpac.a, as demonstrated by MP4Box.
CVSS 7.8
CVE-2019-12482 WRITEUP HIGH
Debian Linux < 0.7.1 - NULL Pointer Dereference
An issue was discovered in GPAC 0.7.1. There is a NULL pointer dereference in the function gf_isom_get_original_format_type at isomedia/drm_sample.c in libgpac.a, as demonstrated by MP4Box.
CVSS 7.5
CVE-2019-12481 WRITEUP MEDIUM
GPAC 0.6.1-0.7.1 - NULL Pointer Dereference in GetESD Function
An issue was discovered in GPAC 0.7.1. There is a NULL pointer dereference in the function GetESD at isomedia/track.c in libgpac.a, as demonstrated by MP4Box.
CVSS 5.5
CVE-2019-11222 WRITEUP HIGH
GPAC 0.7.1 - Out-of-bounds Write in gf_bin128_parse
gf_bin128_parse in utils/os_divers.c in GPAC 0.7.1 has a buffer overflow issue for the crypt feature when encountering a crafted_drm_file.xml file.
CVSS 7.8
CVE-2019-11222 WRITEUP HIGH
GPAC 0.7.1 - Out-of-bounds Write in gf_bin128_parse
gf_bin128_parse in utils/os_divers.c in GPAC 0.7.1 has a buffer overflow issue for the crypt feature when encountering a crafted_drm_file.xml file.
CVSS 7.8
CVE-2019-11221 WRITEUP HIGH
GPAC 0.7.1 - Out-of-bounds Write in gf_import_message
GPAC 0.7.1 has a buffer overflow issue in gf_import_message() in media_import.c.
CVSS 7.8
CVE-2018-7752 WRITEUP HIGH
GPAC < 0.7.1 - Buffer Overflow in gf_media_avc_read_sps
GPAC through 0.7.1 has a Buffer Overflow in the gf_media_avc_read_sps function in media_tools/av_parsers.c, a different vulnerability than CVE-2018-1000100.
CVSS 7.8
CVE-2018-21017 WRITEUP MEDIUM
GPAC 0.7.1 - Use-After-Free in dinf_Read
GPAC 0.7.1 has a memory leak in dinf_Read in isomedia/box_code_base.c.
CVSS 6.5
CVE-2018-21016 WRITEUP MEDIUM
GPAC 0.7.1 - Denial of Service via Crafted File in audio_sample_entry_AddBox
audio_sample_entry_AddBox() at isomedia/box_code_base.c in GPAC 0.7.1 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.
CVSS 6.5
CVE-2018-21015 WRITEUP MEDIUM
GPAC 0.7.1 - Denial of Service via NULL Pointer Dereference in AVC_DuplicateConfig
AVC_DuplicateConfig() at isomedia/avc_ext.c in GPAC 0.7.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file. There is "cfg_new->AVCLevelIndication = cfg->AVCLevelIndication;" but cfg could be NULL.
CVSS 6.5
CVE-2018-20763 WRITEUP HIGH
GPAC < 0.7.1 - Out-of-bounds Write in gf_text_get_utf8_line
In GPAC 0.7.1 and earlier, gf_text_get_utf8_line in media_tools/text_import.c in libgpac_static.a allows an out-of-bounds write because of missing szLineConv bounds checking.
CVSS 7.8
CVE-2018-20762 WRITEUP HIGH
GPAC < 0.7.1 - Buffer Overflow via Crafted Filenames in MP4Box
GPAC version 0.7.1 and earlier has a buffer overflow vulnerability in the cat_multiple_files function in applications/mp4box/fileimport.c when MP4Box is used for a local directory containing crafted filenames.
CVSS 7.8
CVE-2018-20761 WRITEUP HIGH
GPAC < 0.7.1 - Buffer Overflow in gf_sm_load_init
GPAC version 0.7.1 and earlier has a Buffer Overflow vulnerability in the gf_sm_load_init function in scene_manager.c in libgpac_static.a.
CVSS 7.8