CVE-2022-3222
- EPSS 0.08%
- Published 15.09.2022 09:15:09
- Last modified 21.11.2024 07:19:05
Uncontrolled Recursion in GitHub repository gpac/gpac prior to 2.1.0-DEV.
CVE-2022-3178
- EPSS 0.15%
- Published 12.09.2022 17:15:08
- Last modified 21.11.2024 07:18:59
Buffer Over-read in GitHub repository gpac/gpac prior to 2.1.0-DEV.
CVE-2022-38530
- EPSS 0.04%
- Published 06.09.2022 23:15:09
- Last modified 21.11.2024 07:16:37
GPAC v2.1-DEV-rev232-gfcaa01ebb-master was discovered to contain a stack overflow when processing ISOM_IOD.
CVE-2022-36191
- EPSS 0.03%
- Published 17.08.2022 16:15:07
- Last modified 21.11.2024 07:12:34
A heap-buffer-overflow had occurred in function gf_isom_dovi_config_get of isomedia/avc_ext.c:2490, as demonstrated by MP4Box. This vulnerability was fixed in commit fef6242.
CVE-2022-36186
- EPSS 0.29%
- Published 17.08.2022 15:15:08
- Last modified 21.11.2024 07:12:34
A Null Pointer dereference vulnerability exists in GPAC 2.1-DEV-revUNKNOWN-master via the function gf_filter_pid_set_property_full () at filter_core/filter_pid.c:5250,which causes a Denial of Service (DoS). This vulnerability was fixed in commit b43f...
CVE-2022-36190
- EPSS 0.11%
- Published 17.08.2022 15:15:08
- Last modified 21.11.2024 07:12:34
GPAC mp4box 2.1-DEV-revUNKNOWN-master has a use-after-free vulnerability in function gf_isom_dovi_config_get. This vulnerability was fixed in commit fef6242.
CVE-2022-2549
- EPSS 0.13%
- Published 27.07.2022 15:15:08
- Last modified 21.11.2024 07:01:13
NULL Pointer Dereference in GitHub repository gpac/gpac prior to v2.1.0-DEV.
CVE-2022-2453
- EPSS 0.05%
- Published 19.07.2022 14:15:08
- Last modified 21.11.2024 07:01:01
Use After Free in GitHub repository gpac/gpac prior to 2.1-DEV.
CVE-2022-2454
- EPSS 0.04%
- Published 19.07.2022 14:15:08
- Last modified 21.11.2024 07:01:01
Integer Overflow or Wraparound in GitHub repository gpac/gpac prior to 2.1-DEV.
CVE-2021-40606
- EPSS 0.06%
- Published 28.06.2022 13:15:09
- Last modified 21.11.2024 06:24:27
The gf_bs_write_data function in GPAC 1.0.1 allows attackers to cause a denial of service via a crafted file in the MP4Box command.