CVE-2021-21860
- EPSS 0.21%
- Published 16.08.2021 20:15:48
- Last modified 21.11.2024 05:49:07
An exploitable integer truncation vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an improper memory allocation resulting in a heap-based...
CVE-2021-21861
- EPSS 0.42%
- Published 16.08.2021 20:15:48
- Last modified 21.11.2024 05:49:07
An exploitable integer truncation vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. When processing the 'hdlr' FOURCC code, a specially crafted MPEG-4 input can cause an improper mem...
CVE-2021-32439
- EPSS 0.3%
- Published 11.08.2021 20:15:09
- Last modified 21.11.2024 06:07:03
Buffer overflow in the stbl_AppendSize function in MP4Box in GPAC 1.0.1 allows attackers to cause a denial of service or execute arbitrary code via a crafted file.
CVE-2021-32440
- EPSS 0.25%
- Published 11.08.2021 20:15:09
- Last modified 21.11.2024 06:07:03
The Media_RewriteODFrame function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.
CVE-2021-32437
- EPSS 0.25%
- Published 11.08.2021 20:15:08
- Last modified 21.11.2024 06:07:03
The gf_hinter_finalize function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.
CVE-2021-32438
- EPSS 0.25%
- Published 11.08.2021 20:15:08
- Last modified 21.11.2024 06:07:03
The gf_media_export_filters function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.
CVE-2021-36584
- EPSS 0.11%
- Published 05.08.2021 20:15:09
- Last modified 21.11.2024 06:13:51
An issue was discovered in GPAC 1.0.1. There is a heap-based buffer overflow in the function gp_rtp_builder_do_tx3g function in ietf/rtp_pck_3gpp.c, as demonstrated by MP4Box. This can cause a denial of service (DOS).
CVE-2020-22352
- EPSS 0.15%
- Published 04.08.2021 21:15:08
- Last modified 21.11.2024 05:13:15
The gf_dash_segmenter_probe_input function in GPAC v0.8 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.
CVE-2020-24829
- EPSS 0.13%
- Published 04.08.2021 21:15:08
- Last modified 05.03.2025 23:15:13
An issue was discovered in GPAC from v0.5.2 to v0.8.0, as demonstrated by MP4Box. It contains a heap-based buffer overflow in gf_m2ts_section_complete in media_tools/mpegts.c that can cause a denial of service (DOS) via a crafted MP4 file.
CVE-2020-19481
- EPSS 0.27%
- Published 21.07.2021 18:15:08
- Last modified 21.11.2024 05:09:12
An issue was discovered in GPAC before 0.8.0, as demonstrated by MP4Box. It contains an invalid memory read in gf_m2ts_process_pmt in media_tools/mpegts.c that can cause a denial of service via a crafted MP4 file.