Vulnerabilities
Vulnerable Software
Gpac:  Security Vulnerabilities
An issue was discovered in gpac 0.8.0. The gf_media_nalu_remove_emulation_bytes function in av_parsers.c has a heap-based buffer overflow which can lead to a denial of service (DOS) via a crafted input.
CVSS Score
5.5
EPSS Score
0.008
Published
2021-10-12
Memory leak in the sgpd_parse_entry function in MP4Box in gpac 0.8.0 allows attackers to cause a denial of service (DoS) via a crafted input.
CVSS Score
5.5
EPSS Score
0.008
Published
2021-10-12
There is a stack buffer overflow in MP4Box v1.0.1 at src/filters/dmx_nhml.c:1004 in the nhmldmx_send_sample() function szXmlTo parameter which leads to a denial of service vulnerability.
CVSS Score
7.5
EPSS Score
0.012
Published
2021-10-01
There is a stack buffer overflow in MP4Box 1.1.0 at src/filters/dmx_nhml.c in nhmldmx_init_parsing which leads to a denial of service vulnerability.
CVSS Score
7.5
EPSS Score
0.012
Published
2021-10-01
There is a stack buffer overflow in MP4Box v1.0.1 at src/filters/dmx_nhml.c:1008 in the nhmldmx_send_sample() function szXmlFrom parameter which leads to a denial of service vulnerability.
CVSS Score
7.5
EPSS Score
0.013
Published
2021-10-01
An issue was discovered in gpac 0.8.0. The OD_ReadUTF8String function in odf_code.c has a heap-based buffer overflow which can lead to a denial of service (DOS) via a crafted media file.
CVSS Score
5.5
EPSS Score
0.006
Published
2021-09-22
An issue was discovered in gpac 0.8.0. The gf_hinter_track_process function in isom_hinter_track_process.c has a heap-based buffer overflow which can lead to a denial of service (DOS) via a crafted media file
CVSS Score
7.1
EPSS Score
0.007
Published
2021-09-22
An issue was discovered in gpac 0.8.0. The stbl_GetSampleSize function in isomedia/stbl_read.c has a heap-based buffer overflow which can lead to a denial of service (DOS) via a crafted media file.
CVSS Score
5.5
EPSS Score
0.006
Published
2021-09-22
An issue was discovered in gpac through 20200801. A NULL pointer dereference exists in the function ilst_item_box_dump located in box_dump.c. It allows an attacker to cause Denial of Service.
CVSS Score
5.5
EPSS Score
0.006
Published
2021-09-20
An issue was discovered in gpac through 20200801. A NULL pointer dereference exists in the function vwid_box_del located in box_code_base.c. It allows an attacker to cause Denial of Service.
CVSS Score
5.5
EPSS Score
0.006
Published
2021-09-20


Contact Us

Shodan ® - All rights reserved