CVE-2026-1416
- EPSS 0.01%
- Veröffentlicht 26.01.2026 03:02:07
- Zuletzt bearbeitet 29.04.2026 01:00:01
A security flaw has been discovered in GPAC up to 2.4.0. Affected by this vulnerability is the function DumpMovieInfo of the file applications/mp4box/filedump.c. The manipulation results in null pointer dereference. The attack must be initiated from ...
CVE-2026-1415
- EPSS 0.03%
- Veröffentlicht 26.01.2026 02:32:08
- Zuletzt bearbeitet 29.04.2026 01:00:01
A vulnerability was identified in GPAC up to 2.4.0. Affected is the function gf_media_export_webvtt_metadata of the file src/media_tools/media_export.c. The manipulation of the argument Name leads to null pointer dereference. The attack must be carri...
CVE-2025-70305
- EPSS 0.01%
- Veröffentlicht 15.01.2026 17:16:05
- Zuletzt bearbeitet 23.01.2026 17:35:08
A stack overflow in the dmx_saf function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted .saf file.
CVE-2025-70309
- EPSS 0.04%
- Veröffentlicht 15.01.2026 00:00:00
- Zuletzt bearbeitet 23.01.2026 17:34:42
A stack overflow in the pcmreframe_flush_packet function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted WAV file.
CVE-2025-70304
- EPSS 0.06%
- Veröffentlicht 15.01.2026 00:00:00
- Zuletzt bearbeitet 23.01.2026 17:36:45
A buffer overflow in the vobsub_get_subpic_duration() function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted packet.
CVE-2025-70308
- EPSS 0.17%
- Veröffentlicht 15.01.2026 00:00:00
- Zuletzt bearbeitet 23.01.2026 17:34:53
An out-of-bounds read in the GSF demuxer filter component of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted .gsf file.
CVE-2025-70310
- EPSS 0.04%
- Veröffentlicht 15.01.2026 00:00:00
- Zuletzt bearbeitet 23.01.2026 17:34:23
A heap overflow in the vorbis_to_intern() function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted .ogg file.
CVE-2025-70298
- EPSS 0.03%
- Veröffentlicht 15.01.2026 00:00:00
- Zuletzt bearbeitet 23.01.2026 17:37:19
GPAC v2.4.0 was discovered to contain an out-of-bounds read in the oggdmx_parse_tags function.
CVE-2025-70307
- EPSS 0.02%
- Veröffentlicht 15.01.2026 00:00:00
- Zuletzt bearbeitet 30.01.2026 17:58:53
A stack overflow in the dump_ttxt_sample function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted packet.
CVE-2025-70299
- EPSS 0.03%
- Veröffentlicht 15.01.2026 00:00:00
- Zuletzt bearbeitet 30.01.2026 17:58:42
A heap overflow in the avi_parse_input_file() function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted AVI file.