CVE-2026-33144
- EPSS 0.02%
- Veröffentlicht 20.03.2026 20:07:58
- Zuletzt bearbeitet 23.03.2026 14:32:02
GPAC is an open-source multimedia framework. Prior to commit 86b0e36, a heap-based buffer overflow (write) vulnerability was discovered in GPAC MP4Box. The vulnerability exists in the gf_xml_parse_bit_sequence_bs function in utils/xml_bin_custom.c wh...
CVE-2026-4185
- EPSS 0.07%
- Veröffentlicht 15.03.2026 18:32:08
- Zuletzt bearbeitet 16.03.2026 14:53:07
A vulnerability was found in GPAC up to 2.5-DEV-rev2167-gcc9d617c0-master. This vulnerability affects the function swf_def_bits_jpeg of the file src/scene_manager/swf_parse.c of the component MP4Box. The manipulation of the argument szName results in...
CVE-2026-4016
- EPSS 0.01%
- Veröffentlicht 12.03.2026 08:32:13
- Zuletzt bearbeitet 12.03.2026 21:07:53
A security vulnerability has been detected in GPAC 26.03-DEV. Affected by this vulnerability is the function svgin_process of the file src/filters/load_svg.c of the component SVG Parser. The manipulation leads to out-of-bounds write. Local access is ...
CVE-2026-4015
- EPSS 0.01%
- Veröffentlicht 12.03.2026 08:32:09
- Zuletzt bearbeitet 12.03.2026 21:07:53
A weakness has been identified in GPAC 26.03-DEV. Affected is the function txtin_process_texml of the file src/filters/load_text.c of the component TeXML File Parser. Executing a manipulation can lead to stack-based buffer overflow. It is possible to...
CVE-2026-27821
- EPSS 0.03%
- Veröffentlicht 26.02.2026 00:16:26
- Zuletzt bearbeitet 11.03.2026 23:23:32
GPAC is an open-source multimedia framework. In versions up to and including 26.02.0, a stack buffer overflow occurs during NHML file parsing in `src/filters/dmx_nhml.c`. The value of the xmlHeaderEnd XML attribute is copied from att->value into szXm...
CVE-2026-1418
- EPSS 0.01%
- Veröffentlicht 26.01.2026 04:02:06
- Zuletzt bearbeitet 23.02.2026 09:16:54
A security vulnerability has been detected in GPAC up to 2.4.0. This affects the function gf_text_import_srt_bifs of the file src/scene_manager/text_to_bifs.c of the component SRT Subtitle Import. Such manipulation leads to out-of-bounds write. The a...
CVE-2026-1417
- EPSS 0.01%
- Veröffentlicht 26.01.2026 03:32:07
- Zuletzt bearbeitet 23.02.2026 09:16:54
A weakness has been identified in GPAC up to 2.4.0. Affected by this issue is the function dump_isom_rtp of the file applications/mp4box/filedump.c. This manipulation causes null pointer dereference. The attack needs to be launched locally. The explo...
CVE-2026-1416
- EPSS 0.01%
- Veröffentlicht 26.01.2026 03:02:07
- Zuletzt bearbeitet 23.02.2026 09:16:54
A security flaw has been discovered in GPAC up to 2.4.0. Affected by this vulnerability is the function DumpMovieInfo of the file applications/mp4box/filedump.c. The manipulation results in null pointer dereference. The attack must be initiated from ...
CVE-2026-1415
- EPSS 0.02%
- Veröffentlicht 26.01.2026 02:32:08
- Zuletzt bearbeitet 23.02.2026 09:16:54
A vulnerability was identified in GPAC up to 2.4.0. Affected is the function gf_media_export_webvtt_metadata of the file src/media_tools/media_export.c. The manipulation of the argument Name leads to null pointer dereference. The attack must be carri...
CVE-2025-70305
- EPSS 0.01%
- Veröffentlicht 15.01.2026 17:16:05
- Zuletzt bearbeitet 23.01.2026 17:35:08
A stack overflow in the dmx_saf function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted .saf file.