Vulnerabilities > Gpac

DATE CVE VULNERABILITY TITLE RISK
2022-06-28 CVE-2021-40606 Resource Exhaustion vulnerability in Gpac
The gf_bs_write_data function in GPAC 1.0.1 allows attackers to cause a denial of service via a crafted file in the MP4Box command.
network
gpac CWE-400
4.3
2022-06-28 CVE-2021-40607 Allocation of Resources Without Limits or Throttling vulnerability in Gpac
The schm_box_size function in GPAC 1.0.1 allows attackers to cause a denial of service via a crafted file in the MP4Box command.
network
gpac CWE-770
4.3
2022-06-28 CVE-2021-40608 Use of Uninitialized Resource vulnerability in Gpac
The gf_hinter_track_finalize function in GPAC 1.0.1 allows attackers to cause a denial of service via a crafted file in the MP4Box command.
network
gpac CWE-908
4.3
2022-06-28 CVE-2021-40609 Allocation of Resources Without Limits or Throttling vulnerability in Gpac
The GetHintFormat function in GPAC 1.0.1 allows attackers to cause a denial of service via a crafted file in the MP4Box command.
network
gpac CWE-770
4.3
2022-06-28 CVE-2021-40944 NULL Pointer Dereference vulnerability in Gpac 1.1.0
In GPAC MP4Box 1.1.0, there is a Null pointer reference in the function gf_filter_pid_get_packet function in src/filter_core/filter_pid.c:5394, as demonstrated by GPAC.
network
gpac CWE-476
4.3
2022-06-27 CVE-2021-40942 Out-of-bounds Write vulnerability in Gpac 1.1.0
In GPAC MP4Box v1.1.0, there is a heap-buffer-overflow in the function filter_parse_dyn_args function in filter_core/filter.c:1454, as demonstrated by GPAC.
network
gpac CWE-787
4.3
2022-06-16 CVE-2021-41458 Out-of-bounds Write vulnerability in Gpac Mp4Box 1.1.0
In GPAC MP4Box v1.1.0, there is a stack buffer overflow at src/utils/error.c:1769 which leads to a denial of service vulnerability.
network
gpac CWE-787
4.3
2022-06-08 CVE-2021-40592 Infinite Loop vulnerability in Gpac
GPAC version before commit 71460d72ec07df766dab0a4d52687529f3efcf0a (version v1.0.1 onwards) contains loop with unreachable exit condition ('infinite loop') vulnerability in ISOBMFF reader filter, isoffin_read.c.
network
gpac CWE-835
4.3
2022-05-18 CVE-2022-1795 Use After Free vulnerability in Gpac
Use After Free in GitHub repository gpac/gpac prior to v2.1.0-DEV.
network
low complexity
gpac CWE-416
7.5
2022-05-18 CVE-2022-30976 Out-of-bounds Read vulnerability in Gpac 2.0.0
GPAC 2.0.0 misuses a certain Unicode utf8_wcslen (renamed gf_utf8_wcslen) function in utils/utf.c, resulting in a heap-based buffer over-read, as demonstrated by MP4Box.
network
high complexity
gpac CWE-125
4.0