Total
330 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2024-0322 | 1 Gpac | 1 Gpac | 2024-01-11 | N/A | 9.1 CRITICAL |
Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.3-DEV. | |||||
CVE-2023-47465 | 1 Gpac | 1 Gpac | 2023-12-12 | N/A | 5.5 MEDIUM |
An issue in GPAC v.2.2.1 and before allows a local attacker to cause a denial of service (DoS) via the ctts_box_read function of file src/isomedia/box_code_base.c. | |||||
CVE-2023-48958 | 1 Gpac | 1 Gpac | 2023-12-12 | N/A | 5.5 MEDIUM |
gpac 2.3-DEV-rev617-g671976fcc-master contains memory leaks in gf_mpd_resolve_url media_tools/mpd.c:4589. | |||||
CVE-2023-46871 | 1 Gpac | 1 Gpac | 2023-12-12 | N/A | 5.3 MEDIUM |
GPAC version 2.3-DEV-rev602-ged8424300-master in MP4Box contains a memory leak in NewSFDouble scenegraph/vrml_tools.c:300. This vulnerability may lead to a denial of service. | |||||
CVE-2023-48090 | 1 Gpac | 1 Gpac | 2023-11-30 | N/A | 7.1 HIGH |
GPAC 2.3-DEV-rev617-g671976fcc-master is vulnerable to memory leaks in extract_attributes media_tools/m3u8.c:329. | |||||
CVE-2023-48039 | 1 Gpac | 1 Gpac | 2023-11-30 | N/A | 5.5 MEDIUM |
GPAC 2.3-DEV-rev617-g671976fcc-master is vulnerable to memory leak in gf_mpd_parse_string media_tools/mpd.c:75. | |||||
CVE-2023-48013 | 1 Gpac | 1 Gpac | 2023-11-22 | N/A | 7.8 HIGH |
GPAC v2.3-DEV-rev566-g50c2ab06f-master was discovered to contain a double free via the gf_filterpacket_del function at /gpac/src/filter_core/filter.c. | |||||
CVE-2023-48014 | 1 Gpac | 1 Gpac | 2023-11-22 | N/A | 7.8 HIGH |
GPAC v2.3-DEV-rev566-g50c2ab06f-master was discovered to contain a stack overflow via the hevc_parse_vps_extension function at /media_tools/av_parsers.c. | |||||
CVE-2023-5998 | 1 Gpac | 1 Gpac | 2023-11-15 | N/A | 7.5 HIGH |
Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.3.0-DEV. | |||||
CVE-2022-4202 | 1 Gpac | 1 Gpac | 2023-11-07 | N/A | 8.8 HIGH |
A vulnerability, which was classified as problematic, was found in GPAC 2.1-DEV-rev490-g68064e101-master. Affected is the function lsr_translate_coords of the file laser/lsr_dec.c. The manipulation leads to integer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The name of the patch is b3d821c4ae9ba62b3a194d9dcb5e99f17bd56908. It is recommended to apply a patch to fix this issue. VDB-214518 is the identifier assigned to this vulnerability. | |||||
CVE-2022-3957 | 1 Gpac | 1 Gpac | 2023-11-07 | N/A | 6.5 MEDIUM |
A vulnerability classified as problematic was found in GPAC. Affected by this vulnerability is the function svg_parse_preserveaspectratio of the file scenegraph/svg_attributes.c of the component SVG Parser. The manipulation leads to memory leak. The attack can be launched remotely. The name of the patch is 2191e66aa7df750e8ef01781b1930bea87b713bb. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-213463. | |||||
CVE-2023-5595 | 1 Gpac | 1 Gpac | 2023-10-20 | N/A | 5.5 MEDIUM |
Denial of Service in GitHub repository gpac/gpac prior to 2.3.0-DEV. | |||||
CVE-2023-5586 | 1 Gpac | 1 Gpac | 2023-10-19 | N/A | 7.8 HIGH |
NULL Pointer Dereference in GitHub repository gpac/gpac prior to 2.3.0-DEV. | |||||
CVE-2023-42298 | 1 Gpac | 1 Gpac | 2023-10-17 | N/A | 5.5 MEDIUM |
An issue in GPAC GPAC v.2.2.1 and before allows a local attacker to cause a denial of service via the Q_DecCoordOnUnitSphere function of file src/bifs/unquantize.c. | |||||
CVE-2021-40606 | 1 Gpac | 1 Gpac | 2023-08-08 | 4.3 MEDIUM | 5.5 MEDIUM |
The gf_bs_write_data function in GPAC 1.0.1 allows attackers to cause a denial of service via a crafted file in the MP4Box command. | |||||
CVE-2021-45763 | 1 Gpac | 1 Gpac | 2023-08-08 | 4.3 MEDIUM | 5.5 MEDIUM |
GPAC v1.1.0 was discovered to contain an invalid call in the function gf_node_changed(). This vulnerability can lead to a Denial of Service (DoS). | |||||
CVE-2021-45289 | 1 Gpac | 1 Gpac | 2023-08-08 | 4.3 MEDIUM | 5.5 MEDIUM |
A vulnerability exists in GPAC 1.0.1 due to an omission of security-relevant Information, which could cause a Denial of Service. The program terminates with signal SIGKILL. | |||||
CVE-2023-3012 | 1 Gpac | 1 Gpac | 2023-07-15 | N/A | 7.8 HIGH |
NULL Pointer Dereference in GitHub repository gpac/gpac prior to 2.2.2. | |||||
CVE-2023-0760 | 1 Gpac | 1 Gpac | 2023-07-15 | N/A | 7.8 HIGH |
Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to V2.1.0-DEV. | |||||
CVE-2023-3291 | 1 Gpac | 1 Gpac | 2023-07-15 | N/A | 3.3 LOW |
Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.2.2. |