CVE-2026-79513
- EPSS 0.21%
- Veröffentlicht 09.09.2026 00:00:00
- Zuletzt bearbeitet 15.09.2026 17:03:15
A divide-by-zero vulnerability in the gf_dash_get_timeline_duration function (src/media_tools/dash_client.c) of GPAC v26.07.0 allows attackers to cause a Denial of Service (DoS) via a crafted MPD SegmentTimeline. Fixed in 2fd5a06ab226767900fd86edb5a1...
CVE-2026-79514
- EPSS 0.24%
- Veröffentlicht 09.09.2026 00:00:00
- Zuletzt bearbeitet 15.09.2026 17:03:02
An out-of-bounds read in the gf_dm_data_received function (downloader.c) of GPAC v26.07.0 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request. Fixed in 2fd5a06ab226767900fd86edb5a1e8bfc1010640.
CVE-2026-79522
- EPSS 0.24%
- Veröffentlicht 09.09.2026 00:00:00
- Zuletzt bearbeitet 15.09.2026 17:01:40
An out-of-bounds read in the gf_dm_get_chunk_data function (src/utils/downloader.c) of GPAC v26.07.0 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request. Fixed in 2fd5a06ab226767900fd86edb5a1e8bfc1010640.
CVE-2026-52489
- EPSS 0.19%
- Veröffentlicht 25.08.2026 00:00:00
- Zuletzt bearbeitet 09.09.2026 16:03:22
Buffer Overflow vulnerability in gpac 31becc9e08b88e525a4a62013a4000de1c0f8fd9 allows an attacker to execute arbitrary code via the svgNameToImplementationName() function
CVE-2026-15185
- EPSS 0.11%
- Veröffentlicht 09.07.2026 12:30:08
- Zuletzt bearbeitet 09.07.2026 16:19:45
A vulnerability was determined in GPAC 26.03-DEV. This affects the function vobsub_read_idx of the file /src/media_tools/vobsub.c of the component MP4Box. Executing a manipulation of the argument num_langs can lead to out-of-bounds read. The attack n...
CVE-2026-50810
- EPSS 0.12%
- Veröffentlicht 07.07.2026 00:00:00
- Zuletzt bearbeitet 10.07.2026 18:50:20
A NULL pointer dereference in smooth_parse_stream_index() in src/media_tools/mpd.c in GPAC master HEAD before commit b35c61f104b85fbb16520ac2838d5d2ef70845b5 allows attackers to cause a denial of service
CVE-2025-15668
- EPSS 0.12%
- Veröffentlicht 06.07.2026 11:45:07
- Zuletzt bearbeitet 07.07.2026 15:16:41
A vulnerability was identified in GPAC up to b40ce70f5. This issue affects the function sgpd_del_entry of the file src/isomedia/box_code_base.c of the component MP4Box. Such manipulation of the argument data leads to heap-based buffer overflow. Local...
CVE-2025-15667
- EPSS 0.11%
- Veröffentlicht 06.07.2026 11:15:08
- Zuletzt bearbeitet 05.10.2026 16:10:00
A vulnerability was determined in GPAC up to 2.5-DEV. This vulnerability affects the function gf_isom_nalu_sample_rewrite of the file src/isomedia/avc_ext.c of the component MP4Box. This manipulation of the argument nalu_out_bs causes double free. It...
CVE-2026-14801
- EPSS 0.11%
- Veröffentlicht 06.07.2026 06:15:07
- Zuletzt bearbeitet 06.07.2026 18:02:49
A security vulnerability has been detected in GPAC 26.03-DEV-rev342-g80071f700-master. The impacted element is the function txtin_probe_duration of the file src/filters/load_text.c of the component TeXML File Handler. Such manipulation of the argumen...
CVE-2026-14790
- EPSS 0.12%
- Veröffentlicht 06.07.2026 02:15:09
- Zuletzt bearbeitet 06.07.2026 18:02:49
A flaw has been found in GPAC 26.02.0. This affects the function nhmldump_send_frame of the file src/filters/write_nhml.c of the component Media File Handler. Executing a manipulation can lead to null pointer dereference. The attack requires local ac...