CVE-2026-8124
- EPSS 0.02%
- Veröffentlicht 08.05.2026 01:15:10
- Zuletzt bearbeitet 14.05.2026 18:02:30
A security vulnerability has been detected in GPAC up to 26.02.0. This affects the function sidx_box_read of the file src/isomedia/box_code_base.c. The manipulation leads to allocation of resources. The attack must be carried out locally. The exploit...
CVE-2026-39103
- EPSS 0.02%
- Veröffentlicht 05.05.2026 16:16:12
- Zuletzt bearbeitet 07.05.2026 15:15:06
Buffer Overflow vulnerability in GPAC before commit v391dc7f4d234988ea0bc3cc294eb725eddf8f702 allows an attacker to cause a denial of service via the src/scenegraph/svg_attributes.c, svg_parse_strings(), gf_svg_parse_attribute()
CVE-2026-7135
- EPSS 0.01%
- Veröffentlicht 27.04.2026 15:15:11
- Zuletzt bearbeitet 29.04.2026 01:00:01
A security flaw has been discovered in GPAC up to 26.03-DEV-rev105-g8f39a1eb3-master. Affected by this vulnerability is the function elng_box_read of the file src/isomedia/box_code_base.c of the component MP4Box. Performing a manipulation of the argu...
CVE-2026-33144
- EPSS 0.02%
- Veröffentlicht 20.03.2026 20:07:58
- Zuletzt bearbeitet 14.04.2026 18:21:42
GPAC is an open-source multimedia framework. Prior to commit 86b0e36, a heap-based buffer overflow (write) vulnerability was discovered in GPAC MP4Box. The vulnerability exists in the gf_xml_parse_bit_sequence_bs function in utils/xml_bin_custom.c wh...
CVE-2026-4185
- EPSS 0.08%
- Veröffentlicht 15.03.2026 18:32:08
- Zuletzt bearbeitet 29.04.2026 01:00:01
A vulnerability was found in GPAC up to 2.5-DEV-rev2167-gcc9d617c0-master. This vulnerability affects the function swf_def_bits_jpeg of the file src/scene_manager/swf_parse.c of the component MP4Box. The manipulation of the argument szName results in...
CVE-2026-4016
- EPSS 0.02%
- Veröffentlicht 12.03.2026 08:32:13
- Zuletzt bearbeitet 29.04.2026 01:00:01
A security vulnerability has been detected in GPAC 26.03-DEV. Affected by this vulnerability is the function svgin_process of the file src/filters/load_svg.c of the component SVG Parser. The manipulation leads to out-of-bounds write. Local access is ...
CVE-2026-4015
- EPSS 0.02%
- Veröffentlicht 12.03.2026 08:32:09
- Zuletzt bearbeitet 29.04.2026 01:00:01
A weakness has been identified in GPAC 26.03-DEV. Affected is the function txtin_process_texml of the file src/filters/load_text.c of the component TeXML File Parser. Executing a manipulation can lead to stack-based buffer overflow. It is possible to...
CVE-2026-27821
- EPSS 0.05%
- Veröffentlicht 26.02.2026 00:16:26
- Zuletzt bearbeitet 11.03.2026 23:23:32
GPAC is an open-source multimedia framework. In versions up to and including 26.02.0, a stack buffer overflow occurs during NHML file parsing in `src/filters/dmx_nhml.c`. The value of the xmlHeaderEnd XML attribute is copied from att->value into szXm...
CVE-2026-1418
- EPSS 0.01%
- Veröffentlicht 26.01.2026 04:02:06
- Zuletzt bearbeitet 29.04.2026 01:00:01
A security vulnerability has been detected in GPAC up to 2.4.0. This affects the function gf_text_import_srt_bifs of the file src/scene_manager/text_to_bifs.c of the component SRT Subtitle Import. Such manipulation leads to out-of-bounds write. The a...
CVE-2026-1417
- EPSS 0.01%
- Veröffentlicht 26.01.2026 03:32:07
- Zuletzt bearbeitet 29.04.2026 01:00:01
A weakness has been identified in GPAC up to 2.4.0. Affected by this issue is the function dump_isom_rtp of the file applications/mp4box/filedump.c. This manipulation causes null pointer dereference. The attack needs to be launched locally. The explo...