Search CVE reports


Toggle filters

1 – 10 of 375 results


CVE-2026-1418

Medium priority
Needs evaluation

A security vulnerability has been detected in GPAC up to 2.4.0. This affects the function gf_text_import_srt_bifs of the file src/scene_manager/text_to_bifs.c of the component SRT Subtitle Import. Such manipulation leads to...

1 affected package

gpac

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gpac Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-1417

Medium priority
Needs evaluation

A weakness has been identified in GPAC up to 2.4.0. Affected by this issue is the function dump_isom_rtp of the file applications/mp4box/filedump.c. This manipulation causes null pointer dereference. The attack needs to...

1 affected package

gpac

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gpac Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-1416

Medium priority
Needs evaluation

A security flaw has been discovered in GPAC up to 2.4.0. Affected by this vulnerability is the function DumpMovieInfo of the file applications/mp4box/filedump.c. The manipulation results in null pointer dereference. The attack...

1 affected package

gpac

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gpac Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-1415

Medium priority
Needs evaluation

A vulnerability was identified in GPAC up to 2.4.0. Affected is the function gf_media_export_webvtt_metadata of the file src/media_tools/media_export.c. The manipulation of the argument Name leads to null pointer dereference. The...

1 affected package

gpac

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gpac Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-70303

Medium priority
Needs evaluation

A heap overflow in the uncv_parse_config() function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted MP4 file.

1 affected package

gpac

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gpac Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-70302

Medium priority
Needs evaluation

A heap overflow in the ghi_dmx_declare_opid_bin() function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted input.

1 affected package

gpac

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gpac Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-70307

Medium priority
Needs evaluation

A stack overflow in the dump_ttxt_sample function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted packet.

1 affected package

gpac

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gpac Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-70299

Medium priority
Needs evaluation

A heap overflow in the avi_parse_input_file() function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted AVI file.

1 affected package

gpac

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gpac Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-70310

Medium priority
Needs evaluation

A heap overflow in the vorbis_to_intern() function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted .ogg file.

1 affected package

gpac

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gpac Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-70309

Medium priority
Needs evaluation

A stack overflow in the pcmreframe_flush_packet function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted WAV file.

1 affected package

gpac

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gpac Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages