Vulnerability index

Browse CVEs

353 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Gpac MEDIUM 5.5
CVE-2026-39103

Buffer Overflow vulnerability in GPAC before commit v391dc7f4d234988ea0bc3cc294eb725eddf8f702 allows an attacker to cause a denial of service via the…

Fix: 2026-04-01+
Fix from $1,600 2026-05-05
Gpac HIGH 7.8
CVE-2026-33144

GPAC is an open-source multimedia framework. Prior to commit 86b0e36, a heap-based buffer overflow (write) vulnerability was discovered in GPAC MP4Bo…

Fix: 2026-03-17+
Fix from $1,950 2026-03-20
Gpac HIGH 7.8
CVE-2026-27821

GPAC is an open-source multimedia framework. In versions up to and including 26.02.0, a stack buffer overflow occurs during NHML file parsing in `src…

Fix: after 26.02.0
Fix from $1,950 2026-02-26
Gpac HIGH 7.8
CVE-2026-1418

A security vulnerability has been detected in GPAC up to 2.4.0. This affects the function gf_text_import_srt_bifs of the file src/scene_manager/text_…

Fix: after 2.4.0
Fix from $1,950 2026-01-26
Gpac MEDIUM 5.5
CVE-2025-70302

A heap overflow in the ghi_dmx_declare_opid_bin() function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted input.

No fix yet
Fix from $1,600 2026-01-15
Gpac MEDIUM 5.5
CVE-2025-70303

A heap overflow in the uncv_parse_config() function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted MP4 file.

No fix yet
Fix from $1,600 2026-01-15
Gpac HIGH 7.5
CVE-2025-70307

A stack overflow in the dump_ttxt_sample function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted packet.

No fix yet
Fix from $1,950 2026-01-15
Gpac MEDIUM 6.5
CVE-2025-70299

A heap overflow in the avi_parse_input_file() function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted AVI file.

No fix yet
Fix from $1,600 2026-01-15
Gpac HIGH 7.5
CVE-2025-70308

An out-of-bounds read in the GSF demuxer filter component of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted .gsf file.

No fix yet
Fix from $1,950 2026-01-15
Gpac MEDIUM 5.5
CVE-2025-70309

A stack overflow in the pcmreframe_flush_packet function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted WAV file.

No fix yet
Fix from $1,600 2026-01-15
Gpac MEDIUM 5.5
CVE-2025-70310

A heap overflow in the vorbis_to_intern() function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted .ogg file.

No fix yet
Fix from $1,600 2026-01-15
Gpac HIGH 8.2
CVE-2025-70298

GPAC v2.4.0 was discovered to contain an out-of-bounds read in the oggdmx_parse_tags function.

No fix yet
Fix from $1,950 2026-01-15
Gpac HIGH 7.5
CVE-2025-70304

A buffer overflow in the vobsub_get_subpic_duration() function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted packe…

No fix yet
Fix from $1,950 2026-01-15
Gpac MEDIUM 5.5
CVE-2025-70305

A stack overflow in the dmx_saf function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted .saf file.

No fix yet
Fix from $1,600 2026-01-15
Gpac MEDIUM 5.3
CVE-2025-7797

A vulnerability was found in GPAC up to 2.4. It has been rated as problematic. Affected by this issue is the function gf_dash_download_init_segment o…

Fix: after 2.4.0
Fix from $1,600 2025-07-18
Gpac HIGH 8.4
CVE-2025-25723

Buffer Overflow vulnerability in GPAC version 2.5 allows a local attacker to execute arbitrary code.

Patch available
Fix from $1,950 2025-02-28
Gpac MEDIUM 5.5
CVE-2024-57184

An issue was discovered in GPAC v0.8.0, as demonstrated by MP4Box. It contains a heap-based buffer overflow in gf_m2ts_process_pmt in media_tools/mpe…

Patch available
Fix from $1,600 2025-01-24
Gpac HIGH 7.8
CVE-2024-50664

gpac 2.4 contains a heap-buffer-overflow at isomedia/sample_descs.c:1799 in gf_isom_new_mpha_description in gpac/MP4Box.

No fix yet
Fix from $1,950 2025-01-23
Gpac MEDIUM 5.5
CVE-2024-50665

gpac 2.4 contains a SEGV at src/isomedia/drm_sample.c:1562:96 in isom_cenc_get_sai_by_saiz_saio in MP4Box.

No fix yet
Fix from $1,600 2025-01-23
Gpac MEDIUM 5.5
CVE-2023-4679

A use after free vulnerability exists in GPAC version 2.3-DEV-revrelease, specifically in the gf_filterpacket_del function in filter_core/filter.c at…

Patch available
Fix from $1,600 2024-11-15
Gpac MEDIUM 5.5
CVE-2024-6063

A vulnerability was found in GPAC 2.5-DEV-rev228-g11067ea92-master. It has been classified as problematic. This affects the function m2tsdmx_on_event…

Patch available
Fix from $1,600 2024-06-17
Gpac MEDIUM 5.5
CVE-2024-6064

A vulnerability was found in GPAC 2.5-DEV-rev228-g11067ea92-master. It has been declared as problematic. This vulnerability affects the function xmt_…

Patch available
Fix from $1,600 2024-06-17
Gpac MEDIUM 5.5
CVE-2024-6062

A vulnerability was found in GPAC 2.5-DEV-rev228-g11067ea92-master and classified as problematic. Affected by this issue is the function swf_svg_add_…

Patch available
Fix from $1,600 2024-06-17
Gpac MEDIUM 5.5
CVE-2024-6061

A vulnerability has been found in GPAC 2.5-DEV-rev228-g11067ea92-master and classified as problematic. Affected by this vulnerability is the function…

Patch available
Fix from $1,600 2024-06-17
Gpac MEDIUM 6.2
CVE-2024-28319

gpac 2.3-DEV-rev921-g422b78ecf-master was discovered to contain an out of boundary read vulnerability via gf_dash_setup_period media_tools/dash_clien…

No fix yet
Fix from $1,600 2024-03-15
Gpac HIGH 7.1
CVE-2024-28318

gpac 2.3-DEV-rev921-g422b78ecf-master was discovered to contain a out of boundary write vulnerability via swf_get_string at scene_manager/swf_parse.c…

No fix yet
Fix from $1,950 2024-03-15
Gpac CRITICAL 9.8
CVE-2023-46427

An issue was discovered in gpac version 2.3-DEV-rev588-g7edc40fee-master, allows remote attackers to execute arbitrary code, cause a denial of servic…

No fix yet
Fix from $2,300 2024-03-09
Gpac HIGH 8.8
CVE-2023-46426

Heap-based Buffer Overflow vulnerability in gpac version 2.3-DEV-rev588-g7edc40fee-master, allows remote attackers to execute arbitrary code and caus…

No fix yet
Fix from $1,950 2024-03-09
Gpac HIGH 7.5
CVE-2024-24265

gpac v2.2.1 was discovered to contain a memory leak via the dst_props variable in the gf_filter_pid_merge_properties_internal function.

No fix yet
Fix from $1,950 2024-02-05
Gpac HIGH 7.5
CVE-2024-24266

gpac v2.2.1 was discovered to contain a Use-After-Free (UAF) vulnerability via the dasher_configure_pid function at /src/filters/dasher.c.

No fix yet
Fix from $1,950 2024-02-05