📦 Gpac

by Gpac

🔍 What is Gpac?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-46427

CRITICAL CVSS 9.8 Mar 9, 2024

A null pointer dereference vulnerability in gpac's DASH client component allows remote attackers to execute arbitrary code, cause denial of service, or access sensitive information. This affects syste...

CVE-2024-0321

CRITICAL CVSS 9.8 Jan 8, 2024

A stack-based buffer overflow vulnerability in GPAC multimedia framework allows attackers to execute arbitrary code or cause denial of service by sending specially crafted media files. This affects al...

CVE-2023-46932

CRITICAL CVSS 9.8 Dec 9, 2023

A heap buffer overflow vulnerability in GPAC's MP4Box allows attackers to execute arbitrary code or cause denial of service by exploiting the str2ulong class in avilib.c. This affects users of GPAC ve...

CVE-2023-2838

CRITICAL CVSS 9.1 May 22, 2023

This vulnerability is an out-of-bounds read in the GPAC multimedia framework that could allow attackers to read sensitive memory contents or cause denial of service. It affects systems running GPAC ve...

CVE-2023-2840

CRITICAL CVSS 9.8 May 22, 2023

A NULL pointer dereference vulnerability in GPAC multimedia framework allows attackers to cause denial of service (crash) or potentially execute arbitrary code by processing specially crafted media fi...

CVE-2022-1795

CRITICAL CVSS 9.8 May 18, 2022

CVE-2022-1795 is a use-after-free vulnerability in GPAC multimedia framework that allows attackers to execute arbitrary code or cause denial of service. This affects systems running vulnerable version...

CVE-2020-19751

CRITICAL CVSS 9.1 Sep 7, 2021

CVE-2020-19751 is a heap-based buffer over-read vulnerability in gpac's gf_odf_del_ipmp_tool function that could allow attackers to read sensitive memory contents or cause denial of service. This affe...

CVE-2021-28300

CRITICAL CVSS 9.8 Apr 14, 2021

This vulnerability allows attackers to execute arbitrary code or cause denial-of-service by exploiting a NULL pointer dereference in GPAC's MP4 file parser. Attackers can trigger this by uploading a m...

CVE-2025-70307

HIGH CVSS 7.5 Jan 15, 2026

A stack overflow vulnerability in GPAC's dump_ttxt_sample function allows attackers to cause Denial of Service by sending specially crafted packets. This affects systems running vulnerable versions of...

CVE-2025-70308

HIGH CVSS 7.5 Jan 15, 2026

An out-of-bounds read vulnerability in GPAC's GSF demuxer filter allows attackers to cause denial of service by processing a malicious .gsf file. This affects systems running GPAC v2.4.0 that process ...

CVE-2025-70298

HIGH CVSS 8.2 Jan 15, 2026

CVE-2025-70298 is an out-of-bounds read vulnerability in GPAC's OGG demuxer that could allow attackers to read sensitive memory contents or cause application crashes. This affects systems running GPAC...

CVE-2025-70304

HIGH CVSS 7.5 Jan 15, 2026

A buffer overflow vulnerability in GPAC's vobsub_get_subpic_duration() function allows attackers to cause denial of service by sending specially crafted packets. This affects systems running GPAC v2.4...

CVE-2025-25723

HIGH CVSS 8.4 Feb 28, 2025

A buffer overflow vulnerability in GPAC version 2.5 allows local attackers to execute arbitrary code on affected systems. This affects systems running GPAC 2.5 where an attacker has local access. The ...

CVE-2024-50664

HIGH CVSS 7.8 Jan 23, 2025

This vulnerability is a heap buffer overflow in gpac's MP4Box tool that occurs when processing specially crafted MP4 files. Attackers could exploit this to execute arbitrary code or cause denial of se...

CVE-2024-28318

HIGH CVSS 7.1 Mar 15, 2024

This vulnerability in GPAC multimedia framework allows attackers to write data beyond allocated memory boundaries when processing SWF files. It affects systems running vulnerable versions of GPAC that...

CVE-2024-24265

HIGH CVSS 7.5 Feb 5, 2024

CVE-2024-24265 is a memory leak vulnerability in gpac v2.2.1 that occurs via the dst_props variable in the gf_filter_pid_merge_properties_internal function. This vulnerability could allow attackers to...

CVE-2024-24267

HIGH CVSS 7.5 Feb 5, 2024

This vulnerability in GPAC multimedia framework allows memory exhaustion through a memory leak in the gf_fileio_from_blob function. Attackers could cause denial of service by repeatedly triggering the...

CVE-2023-48090

HIGH CVSS 7.1 Nov 20, 2023

GPAC 2.3-DEV-rev617-g671976fcc-master contains memory leaks in the extract_attributes function when processing M3U8 files. This vulnerability allows attackers to cause denial of service through resour...

CVE-2023-48011

HIGH CVSS 7.8 Nov 15, 2023

CVE-2023-48011 is a heap-use-after-free vulnerability in GPAC's movie_fragments.c that allows attackers to execute arbitrary code or cause denial of service by processing specially crafted media files...

CVE-2023-48014

HIGH CVSS 7.8 Nov 15, 2023

This CVE describes a stack overflow vulnerability in GPAC's HEVC video parser that could allow remote code execution. Attackers could exploit this by crafting malicious HEVC video files. Users and app...

CVE-2023-5998

HIGH CVSS 7.5 Nov 7, 2023

CVE-2023-5998 is an out-of-bounds read vulnerability in the GPAC multimedia framework that could allow attackers to read sensitive memory contents. This affects users and applications running GPAC ver...

CVE-2023-5377

HIGH CVSS 7.1 Oct 4, 2023

This vulnerability is an out-of-bounds read in the GPAC multimedia framework that could allow attackers to read sensitive memory contents. It affects users of GPAC versions prior to v2.2.2-DEV who pro...

CVE-2023-3523

HIGH CVSS 7.1 Jul 6, 2023

This vulnerability is an out-of-bounds read in the GPAC multimedia framework that could allow attackers to read sensitive memory contents. It affects users of GPAC versions prior to 2.2.2 who process ...

CVE-2023-3012

HIGH CVSS 7.8 May 31, 2023

A NULL pointer dereference vulnerability in GPAC multimedia framework allows attackers to cause denial of service (crash) by exploiting improper handling of certain media files. This affects all syste...

CVE-2023-1654

HIGH CVSS 7.8 Mar 27, 2023

This vulnerability in GPAC (Multimedia Framework) allows remote attackers to cause a denial of service via resource exhaustion. It affects systems running GPAC versions prior to 2.4.0, particularly th...

CVE-2023-1655

HIGH CVSS 7.8 Mar 27, 2023

A heap-based buffer overflow vulnerability in GPAC multimedia framework allows attackers to execute arbitrary code or cause denial of service by processing specially crafted media files. This affects ...

CVE-2023-0819

HIGH CVSS 7.8 Feb 13, 2023

This CVE describes a heap-based buffer overflow vulnerability in the GPAC multimedia framework. Attackers can exploit this to execute arbitrary code or cause denial of service by sending specially cra...

CVE-2023-0770

HIGH CVSS 7.8 Feb 9, 2023

This CVE describes a stack-based buffer overflow vulnerability in GPAC multimedia framework versions prior to 2.2. Attackers can exploit this by crafting malicious media files to execute arbitrary cod...

CVE-2022-2454

HIGH CVSS 7.8 Jul 19, 2022

CVE-2022-2454 is an integer overflow vulnerability in the GPAC multimedia framework that could allow attackers to cause denial of service or potentially execute arbitrary code. This affects users and ...

CVE-2022-30976

HIGH CVSS 7.1 May 18, 2022

CVE-2022-30976 is a heap-based buffer over-read vulnerability in GPAC's Unicode handling function. Attackers can exploit this by crafting malicious MP4 files to cause memory corruption, potentially le...

CVE-2022-29339

HIGH CVSS 7.5 May 5, 2022

This vulnerability in GPAC's BS_ReadByte() function causes a failed assertion leading to denial of service when processing malformed media files. It affects systems running vulnerable versions of GPAC...

CVE-2022-1441

HIGH CVSS 7.8 Apr 25, 2022

CVE-2022-1441 is a buffer overflow vulnerability in MP4Box (part of GPAC) that occurs when parsing malicious MP4 files. Attackers can exploit this to execute arbitrary code or cause denial of service....

CVE-2022-24575

HIGH CVSS 7.8 Mar 14, 2022

CVE-2022-24575 is a stack-based buffer overflow vulnerability in GPAC's MP4Box tool that allows attackers to execute arbitrary code or cause denial of service. This affects users who process untrusted...

CVE-2022-26967

HIGH CVSS 7.8 Mar 12, 2022

CVE-2022-26967 is a heap-based buffer overflow vulnerability in GPAC's gf_base64_encode function that can be triggered via MP4Box. This allows attackers to execute arbitrary code or cause denial of se...

CVE-2021-40574

HIGH CVSS 7.8 Jan 13, 2022

CVE-2021-40574 is a double-free vulnerability in Gpac's MP4Box binary that allows attackers to cause denial of service, execute arbitrary code, or escalate privileges. This affects users processing ma...

CVE-2021-40570

HIGH CVSS 7.8 Jan 13, 2022

A double-free vulnerability in Gpac's MP4Box allows attackers to cause denial of service or potentially execute arbitrary code. This affects systems running vulnerable versions of Gpac that process ma...

CVE-2021-40568

HIGH CVSS 7.8 Jan 13, 2022

A buffer overflow vulnerability in Gpac's MP4 file parser allows attackers to execute arbitrary code or cause denial of service by providing a specially crafted MP4 file. This affects all systems runn...

CVE-2021-36412

HIGH CVSS 7.8 Jan 10, 2022

A heap-based buffer overflow vulnerability in GPAC's MP4Box tool allows attackers to execute arbitrary code or cause denial of service by processing a specially crafted MP4 file. This affects systems ...

CVE-2021-45266

HIGH CVSS 7.5 Dec 22, 2021

A null pointer dereference vulnerability in gpac 1.1.0 allows attackers to cause a segmentation fault and crash the application by exploiting the lsr_read_anim_values_ex function. This affects systems...

CVE-2020-23267

HIGH CVSS 7.1 Sep 22, 2021

This vulnerability in GPAC 0.8.0 allows attackers to cause a heap-based buffer overflow by processing a specially crafted media file. This can lead to denial of service (crashing the application) and ...

CVE-2021-32271

HIGH CVSS 7.8 Sep 20, 2021

This vulnerability is a stack buffer overflow in GPAC's DumpRawUIConfig function that allows remote code execution when processing malicious files. Attackers can exploit this by tricking users into op...

CVE-2021-32268

HIGH CVSS 7.8 Sep 20, 2021

This buffer overflow vulnerability in GPAC's gf_fprintf function allows attackers to execute arbitrary code by exploiting improper bounds checking. It affects all systems running GPAC versions before ...

CVE-2021-32136

HIGH CVSS 7.8 Sep 13, 2021

This vulnerability is a heap buffer overflow in GPAC's MP4Box tool that allows attackers to cause denial of service or execute arbitrary code by providing a specially crafted MP4 file. It affects syst...

CVE-2021-21840

HIGH CVSS 8.8 Aug 25, 2021

This integer overflow vulnerability in GPAC's MPEG-4 decoder allows heap-based buffer overflow via specially crafted video files. Attackers can achieve remote code execution by tricking users into ope...

CVE-2021-21842

HIGH CVSS 8.8 Aug 25, 2021

This vulnerability allows remote code execution through a specially crafted MPEG-4 video file. Attackers can exploit an integer overflow in GPAC's MPEG-4 decoder to cause heap corruption and execute a...

CVE-2021-21849

HIGH CVSS 8.8 Aug 25, 2021

An integer overflow vulnerability in GPAC's MPEG-4 decoder allows heap-based buffer overflow via specially crafted video files. Attackers can exploit this by tricking users into opening malicious vide...

CVE-2021-21835

HIGH CVSS 8.8 Aug 25, 2021

This vulnerability allows remote code execution through a specially crafted MPEG-4 video file. Attackers can exploit it by tricking users into opening malicious videos, potentially taking full control...

CVE-2021-21862

HIGH CVSS 8.8 Aug 18, 2021

This vulnerability allows remote code execution through integer truncation in GPAC's MPEG-4 decoder. Attackers can exploit it by tricking users into opening malicious video files. Systems using GPAC v...

CVE-2026-1418

MEDIUM CVSS 5.3 Jan 26, 2026

This CVE describes an out-of-bounds write vulnerability in GPAC's SRT subtitle import function. Attackers with local access can exploit this to potentially execute arbitrary code or crash the applicat...

CVE-2025-70302

MEDIUM CVSS 5.5 Jan 15, 2026

A heap overflow vulnerability in GPAC's ghi_dmx_declare_opid_bin() function allows attackers to cause Denial of Service (DoS) through specially crafted input. This affects systems running GPAC v2.4.0 ...

CVE-2025-70303

MEDIUM CVSS 5.5 Jan 15, 2026

A heap overflow vulnerability in GPAC's uncv_parse_config() function allows attackers to cause Denial of Service (DoS) by providing a specially crafted MP4 file. This affects GPAC v2.4.0 users who pro...

CVE-2025-70299

MEDIUM CVSS 6.5 Jan 15, 2026

A heap overflow vulnerability in GPAC's AVI file parser allows attackers to cause denial of service by providing a specially crafted AVI file. This affects systems running GPAC v2.4.0 that process unt...

CVE-2025-70309

MEDIUM CVSS 5.5 Jan 15, 2026

A stack overflow vulnerability in GPAC's pcmreframe_flush_packet function allows attackers to cause denial of service by processing a specially crafted WAV file. This affects systems running GPAC v2.4...

CVE-2025-70310

MEDIUM CVSS 5.5 Jan 15, 2026

A heap overflow vulnerability in GPAC's vorbis_to_intern() function allows attackers to cause Denial of Service (DoS) by processing a malicious .ogg file. This affects systems running GPAC v2.4.0 for ...

CVE-2025-70305

MEDIUM CVSS 5.5 Jan 15, 2026

A stack overflow vulnerability in GPAC's dmx_saf function allows attackers to cause Denial of Service (DoS) by providing a specially crafted .saf file. This affects systems running GPAC v2.4.0 that pr...

CVE-2025-7797

MEDIUM CVSS 5.3 Jul 18, 2025

A null pointer dereference vulnerability in GPAC's DASH client allows remote attackers to cause denial of service by manipulating the base_init_url argument. This affects GPAC multimedia framework use...

CVE-2024-57184

MEDIUM CVSS 5.5 Jan 24, 2025

A heap-based buffer overflow vulnerability exists in GPAC v0.8.0's MP4Box tool when processing crafted MP4 files. This can cause denial of service (crash) and potentially allow arbitrary code executio...

CVE-2024-50665

MEDIUM CVSS 5.5 Jan 23, 2025

This vulnerability in gpac's MP4Box tool is a NULL pointer dereference that causes a segmentation fault (SEGV) when processing specially crafted MP4 files with DRM encryption. It affects users who pro...

CVE-2023-4679

MEDIUM CVSS 5.5 Nov 15, 2024

A use-after-free vulnerability in GPAC's gf_filterpacket_del function can cause double-free conditions leading to application crashes. This affects systems running GPAC version 2.3-DEV-revrelease when...

CVE-2024-6064

MEDIUM CVSS 5.3 Jun 17, 2024

This vulnerability in GPAC's MP4Box tool is a use-after-free flaw in the xmt_node_end function that could allow local attackers to crash the application or potentially execute arbitrary code. It affec...

CVE-2026-1417

LOW CVSS 3.3 Jan 26, 2026

This CVE describes a null pointer dereference vulnerability in GPAC's MP4Box tool that can cause application crashes. The vulnerability requires local access to exploit and affects GPAC versions up to...

CVE-2026-1416

LOW CVSS 3.3 Jan 26, 2026

A null pointer dereference vulnerability exists in GPAC's DumpMovieInfo function, allowing local attackers to cause denial of service through application crashes. This affects GPAC versions up to 2.4....

CVE-2026-1415

LOW CVSS 3.3 Jan 26, 2026

A null pointer dereference vulnerability exists in GPAC multimedia framework versions up to 2.4.0. Attackers with local access can crash the application by manipulating the Name argument in the gf_med...