CVE-2020-19488
MEDIUMGpac - NULL Pointer Dereference
Title source: ruleDescription
An issue was discovered in box_code_apple.c:119 in Gpac MP4Box 0.8.0, allows attackers to cause a Denial of Service due to an invalid read on function ilst_item_Read.
Scores
CVSS v3
5.5
EPSS
0.0016
EPSS Percentile
37.3%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Classification
CWE
CWE-476
Status
published
Affected Products (1)
gpac/gpac
Timeline
Published
Jul 21, 2021
Tracked Since
Feb 18, 2026