CVE-2026-103227
- EPSS 0.52%
- Veröffentlicht 30.09.2026 14:30:09
- Zuletzt bearbeitet 02.10.2026 17:17:01
A weakness has been identified in GPAC up to 26.07.0. Affected by this issue is the function gf_dash_resolve_url of the file src/media_tools/dash_client.c of the component DASH Client. This manipulation causes buffer overflow. The attack is possible ...
CVE-2026-88339
- EPSS 0.17%
- Veröffentlicht 22.09.2026 00:00:00
- Zuletzt bearbeitet 24.09.2026 21:08:55
A NULL pointer dereference vulnerability exists in the gf_sg_vrml_field_clone() function of GPAC 2d7da22e (26.08-DEV). The vulnerability occurs when cloning a PROTO default SFImage field with a NULL source pointer. An attacker can provide a specially...
CVE-2026-93331
- EPSS 0.31%
- Veröffentlicht 18.09.2026 01:45:14
- Zuletzt bearbeitet 18.09.2026 20:17:31
A vulnerability was identified in GPAC 26.08-DEV. This vulnerability affects the function gf_rtp_parse_ttxt of the file src/ietf/rtp_depacketizer.c of the component RTP Depacketizer. Such manipulation of the argument size leads to out-of-bounds read....
CVE-2026-92475
- EPSS 0.14%
- Veröffentlicht 16.09.2026 19:45:09
- Zuletzt bearbeitet 22.09.2026 16:18:12
A weakness has been identified in GPAC 26.08-DEV. This impacts the function wait_for_header_and_parse of the file src/utils/downloader.c. This manipulation of the argument Content-Range causes out-of-bounds read. The attack requires local access. The...
CVE-2026-92473
- EPSS 0.16%
- Veröffentlicht 16.09.2026 19:18:06
- Zuletzt bearbeitet 18.09.2026 19:17:17
A vulnerability was identified in GPAC 26.08-DEV. The impacted element is the function gf_sg_command_del of the file src/scenegraph/commands.c of the component BIFS Handler. The manipulation leads to use after free. The attack needs to be performed l...
CVE-2026-92474
- EPSS 0.15%
- Veröffentlicht 16.09.2026 19:15:09
- Zuletzt bearbeitet 17.09.2026 21:12:30
A security flaw has been discovered in GPAC 26.08-DEV. This affects the function gf_inline_get_proto_lib of the file src/compositor/mpeg4_inline.c of the component Proto Link Handler. The manipulation results in use after free. The attack requires a ...
CVE-2026-92472
- EPSS 0.16%
- Veröffentlicht 16.09.2026 18:45:09
- Zuletzt bearbeitet 17.09.2026 21:12:30
A vulnerability was determined in GPAC 26.08-DEV. The affected element is the function gf_node_deactivate_ex of the file src/scenegraph/base_scenegraph.c of the component MP4Box. Executing a manipulation can lead to use after free. The attack needs t...
CVE-2026-92399
- EPSS 0.66%
- Veröffentlicht 16.09.2026 16:15:08
- Zuletzt bearbeitet 18.09.2026 18:18:08
A vulnerability was determined in GPAC 26.07.0. This affects the function rmt_client_handle_ws_frame of the file src/utils/rmt_ws.c of the component WebSocket Handler. Executing a manipulation of the argument payload_size can lead to heap-based buffe...
- EPSS 0.39%
- Veröffentlicht 15.09.2026 07:45:10
- Zuletzt bearbeitet 15.09.2026 15:17:31
A vulnerability was identified in GPAC up to f1219cde. The impacted element is the function gf_node_list_insert_child of the file scenegraph/base_scenegraph.c of the component Node Insertion. Such manipulation leads to memory corruption. The attack c...
CVE-2026-91090
- EPSS 0.12%
- Veröffentlicht 15.09.2026 07:30:09
- Zuletzt bearbeitet 17.09.2026 14:17:53
A vulnerability was determined in GPAC up to f1219cde. The affected element is the function gf_node_activate_ex of the file scenegraph/base_scenegraph.c. This manipulation causes stack-based buffer overflow. It is possible to launch the attack on the...