Total
337 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2022-47657 | 1 Gpac | 1 Gpac | 2023-05-27 | N/A | 7.8 HIGH |
GPAC MP4Box 2.1-DEV-rev644-g5c4df2a67 is vulnerable to buffer overflow in function hevc_parse_vps_extension of media_tools/av_parsers.c:7662 | |||||
CVE-2022-47095 | 1 Gpac | 1 Gpac | 2023-05-27 | N/A | 7.8 HIGH |
GPAC MP4box 2.1-DEV-rev574-g9d5bb184b is vulnerable to Buffer overflow in hevc_parse_vps_extension function of media_tools/av_parsers.c | |||||
CVE-2022-47094 | 1 Gpac | 1 Gpac | 2023-05-27 | N/A | 7.8 HIGH |
GPAC MP4box 2.1-DEV-rev574-g9d5bb184b is vulnerable to Null pointer dereference via filters/dmx_m2ts.c:343 in m2tsdmx_declare_pid | |||||
CVE-2022-47091 | 1 Gpac | 1 Gpac | 2023-05-27 | N/A | 7.8 HIGH |
GPAC MP4box 2.1-DEV-rev574-g9d5bb184b is vulnerable to Buffer Overflow in gf_text_process_sub function of filters/load_text.c | |||||
CVE-2022-47086 | 1 Gpac | 1 Gpac | 2023-05-27 | N/A | 5.5 MEDIUM |
GPAC MP4Box v2.1-DEV-rev574-g9d5bb184b contains a segmentation violation via the function gf_sm_load_init_swf at scene_manager/swf_parse.c | |||||
CVE-2022-45343 | 1 Gpac | 1 Gpac | 2023-05-27 | N/A | 7.8 HIGH |
GPAC v2.1-DEV-rev478-g696e6f868-master was discovered to contain a heap use-after-free via the Q_IsTypeOn function at /gpac/src/bifs/unquantize.c. | |||||
CVE-2022-45283 | 1 Gpac | 1 Gpac | 2023-05-27 | N/A | 7.8 HIGH |
GPAC MP4box v2.0.0 was discovered to contain a stack overflow in the smil_parse_time_list parameter at /scenegraph/svg_attributes.c. | |||||
CVE-2022-45202 | 1 Gpac | 1 Gpac | 2023-05-27 | N/A | 7.8 HIGH |
GPAC v2.1-DEV-rev428-gcb8ae46c8-master was discovered to contain a stack overflow via the function dimC_box_read at isomedia/box_code_3gpp.c. | |||||
CVE-2022-43255 | 1 Gpac | 1 Gpac | 2023-05-27 | N/A | 5.5 MEDIUM |
GPAC v2.1-DEV-rev368-gfd054169b-master was discovered to contain a memory leak via the component gf_odf_new_iod at odf/odf_code.c. | |||||
CVE-2022-3222 | 1 Gpac | 1 Gpac | 2023-05-27 | N/A | 5.5 MEDIUM |
Uncontrolled Recursion in GitHub repository gpac/gpac prior to 2.1.0-DEV. | |||||
CVE-2022-38530 | 1 Gpac | 1 Gpac | 2023-05-27 | N/A | 7.8 HIGH |
GPAC v2.1-DEV-rev232-gfcaa01ebb-master was discovered to contain a stack overflow when processing ISOM_IOD. | |||||
CVE-2022-36191 | 1 Gpac | 1 Gpac | 2023-05-27 | N/A | 5.5 MEDIUM |
A heap-buffer-overflow had occurred in function gf_isom_dovi_config_get of isomedia/avc_ext.c:2490, as demonstrated by MP4Box. This vulnerability was fixed in commit fef6242. | |||||
CVE-2022-36190 | 1 Gpac | 1 Gpac | 2023-05-27 | N/A | 9.8 CRITICAL |
GPAC mp4box 2.1-DEV-revUNKNOWN-master has a use-after-free vulnerability in function gf_isom_dovi_config_get. This vulnerability was fixed in commit fef6242. | |||||
CVE-2022-2454 | 1 Gpac | 1 Gpac | 2023-05-27 | N/A | 7.8 HIGH |
Integer Overflow or Wraparound in GitHub repository gpac/gpac prior to 2.1-DEV. | |||||
CVE-2022-29537 | 1 Gpac | 1 Gpac | 2023-05-27 | 4.3 MEDIUM | 5.5 MEDIUM |
gp_rtp_builder_do_hevc in ietf/rtp_pck_mpeg4.c in GPAC 2.0.0 has a heap-based buffer over-read, as demonstrated by MP4Box. | |||||
CVE-2022-27147 | 1 Gpac | 1 Gpac | 2023-05-27 | 4.3 MEDIUM | 5.5 MEDIUM |
GPAC mp4box 1.1.0-DEV-rev1727-g8be34973d-master has a use-after-free vulnerability in function gf_node_get_attribute_by_tag. | |||||
CVE-2022-27145 | 1 Gpac | 1 Gpac | 2023-05-27 | 4.3 MEDIUM | 5.5 MEDIUM |
GPAC mp4box 1.1.0-DEV-rev1727-g8be34973d-master has a stack-overflow vulnerability in function gf_isom_get_sample_for_movie_time of mp4box. | |||||
CVE-2022-26967 | 1 Gpac | 1 Gpac | 2023-05-27 | 6.8 MEDIUM | 7.8 HIGH |
GPAC 2.0 allows a heap-based buffer overflow in gf_base64_encode. It can be triggered via MP4Box. | |||||
CVE-2022-24578 | 1 Gpac | 1 Gpac | 2023-05-27 | 6.8 MEDIUM | 7.8 HIGH |
GPAC 1.0.1 is affected by a heap-based buffer overflow in SFS_AddString () at bifs/script_dec.c. | |||||
CVE-2022-24577 | 1 Gpac | 1 Gpac | 2023-05-27 | 6.8 MEDIUM | 7.8 HIGH |
GPAC 1.0.1 is affected by a NULL pointer dereference in gf_utf8_wcslen. (gf_utf8_wcslen is a renamed Unicode utf8_wcslen function.) |