GPAC 2.1-DEV-rev490-g68064e101-master

CPE Details

GPAC 2.1-DEV-rev490-g68064e101-master
2.1-dev-rev490-g68064e101-master
2022-12-01
12h37 +00:00
2022-12-15
15h38 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:gpac:gpac:2.1-dev-rev490-g68064e101-master:*:*:*:*:*:*:*

Informations

Vendor

gpac

Product

gpac

Version

2.1-dev-rev490-g68064e101-master

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2024-0322 2024-01-08 12h38 +00:00 Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.3-DEV.
9.1
Critical
CVE-2024-0321 2024-01-08 12h10 +00:00 Stack-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.3-DEV.
9.8
Critical
CVE-2023-47465 2023-12-08 23h00 +00:00 An issue in GPAC v.2.2.1 and before allows a local attacker to cause a denial of service (DoS) via the ctts_box_read function of file src/isomedia/box_code_base.c.
5.5
Medium
CVE-2023-46871 2023-12-06 23h00 +00:00 GPAC version 2.3-DEV-rev602-ged8424300-master in MP4Box contains a memory leak in NewSFDouble scenegraph/vrml_tools.c:300. This vulnerability may lead to a denial of service.
5.3
Medium
CVE-2023-5998 2023-11-07 18h45 +00:00 Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.3.0-DEV.
7.5
High
CVE-2023-5595 2023-10-16 08h25 +00:00 Denial of Service in GitHub repository gpac/gpac prior to 2.3.0-DEV.
5.5
Medium
CVE-2023-5586 2023-10-15 00h28 +00:00 NULL Pointer Dereference in GitHub repository gpac/gpac prior to 2.3.0-DEV.
7.8
High
CVE-2023-42298 2023-10-11 22h00 +00:00 An issue in GPAC GPAC v.2.2.1 and before allows a local attacker to cause a denial of service via the Q_DecCoordOnUnitSphere function of file src/bifs/unquantize.c.
5.5
Medium
CVE-2023-5520 2023-10-11 11h56 +00:00 Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.2.2.
7.1
High
CVE-2023-5377 2023-10-04 09h53 +00:00 Out-of-bounds Read in GitHub repository gpac/gpac prior to v2.2.2-DEV.
7.1
High
CVE-2023-41000 2023-09-10 22h00 +00:00 GPAC through 2.2.1 has a use-after-free vulnerability in the function gf_bifs_flush_command_list in bifs/memory_decoder.c.
5.5
Medium
CVE-2023-4778 2023-09-05 15h43 +00:00 Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.3-DEV.
5.5
Medium
CVE-2023-4758 2023-09-04 15h47 +00:00 Buffer Over-read in GitHub repository gpac/gpac prior to 2.3-DEV.
5.5
Medium
CVE-2023-4755 2023-09-04 13h46 +00:00 Use After Free in GitHub repository gpac/gpac prior to 2.3-DEV.
5.5
Medium
CVE-2023-4756 2023-09-04 08h24 +00:00 Stack-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.3-DEV.
5.5
Medium
CVE-2023-4754 2023-09-04 08h24 +00:00 Out-of-bounds Write in GitHub repository gpac/gpac prior to 2.3-DEV.
5.5
Medium
CVE-2023-4722 2023-09-01 15h27 +00:00 Integer Overflow or Wraparound in GitHub repository gpac/gpac prior to 2.3-DEV.
5.5
Medium
CVE-2023-4721 2023-09-01 15h27 +00:00 Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.3-DEV.
5.5
Medium
CVE-2023-4720 2023-09-01 15h27 +00:00 Floating Point Comparison with Incorrect Operator in GitHub repository gpac/gpac prior to 2.3-DEV.
5.5
Medium
CVE-2023-4683 2023-08-31 15h54 +00:00 NULL Pointer Dereference in GitHub repository gpac/gpac prior to 2.3-DEV.
5.5
Medium
CVE-2023-4682 2023-08-31 15h54 +00:00 Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.3-DEV.
5.5
Medium
CVE-2023-4681 2023-08-31 15h53 +00:00 NULL Pointer Dereference in GitHub repository gpac/gpac prior to 2.3-DEV.
5.5
Medium
CVE-2023-4678 2023-08-31 15h47 +00:00 Divide By Zero in GitHub repository gpac/gpac prior to 2.3-DEV.
5.5
Medium
CVE-2023-3523 2023-07-06 09h53 +00:00 Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.2.2.
7.1
High
CVE-2023-3291 2023-06-15 22h00 +00:00 Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.2.2.
3.3
Low
CVE-2023-3012 2023-05-30 22h00 +00:00 NULL Pointer Dereference in GitHub repository gpac/gpac prior to 2.2.2.
7.8
High
CVE-2023-3013 2023-05-30 22h00 +00:00 Unchecked Return Value in GitHub repository gpac/gpac prior to 2.2.2.
7.1
High
CVE-2023-2837 2023-05-21 22h00 +00:00 Stack-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.2.2.
5.5
Medium
CVE-2023-2838 2023-05-21 22h00 +00:00 Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.2.2.
9.1
Critical
CVE-2023-2839 2023-05-21 22h00 +00:00 Divide By Zero in GitHub repository gpac/gpac prior to 2.2.2.
7.5
High
CVE-2023-2840 2023-05-21 22h00 +00:00 NULL Pointer Dereference in GitHub repository gpac/gpac prior to 2.2.2.
9.8
Critical
CVE-2023-1654 2023-03-27 00h00 +00:00 Denial of Service in GitHub repository gpac/gpac prior to 2.4.0.
7.8
High
CVE-2023-1655 2023-03-27 00h00 +00:00 Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.4.0.
7.8
High
CVE-2023-0866 2023-02-16 00h00 +00:00 Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.3.0-DEV.
7.8
High
CVE-2023-0817 2023-02-13 00h00 +00:00 Buffer Over-read in GitHub repository gpac/gpac prior to v2.3.0-DEV.
7.8
High
CVE-2023-0818 2023-02-13 00h00 +00:00 Off-by-one Error in GitHub repository gpac/gpac prior to v2.3.0-DEV.
5.5
Medium
CVE-2023-0819 2023-02-13 00h00 +00:00 Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to v2.3.0-DEV.
7.8
High
CVE-2023-0760 2023-02-09 00h00 +00:00 Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to V2.1.0-DEV.
7.8
High
CVE-2023-0770 2023-02-08 23h00 +00:00 Stack-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.2.
7.8
High
CVE-2023-0358 2023-01-17 23h00 +00:00 Use After Free in GitHub repository gpac/gpac prior to 2.3.0-DEV.
7.8
High
CVE-2022-46489 2023-01-04 23h00 +00:00 GPAC version 2.1-DEV-rev505-gb9577e6ad-master was discovered to contain a memory leak via the gf_isom_box_parse_ex function at box_funcs.c.
5.5
Medium
CVE-2022-46490 2023-01-04 23h00 +00:00 GPAC version 2.1-DEV-rev505-gb9577e6ad-master was discovered to contain a memory leak via the afrt_box_read function at box_code_adobe.c.
5.5
Medium
CVE-2022-47086 2023-01-04 23h00 +00:00 GPAC MP4Box v2.1-DEV-rev574-g9d5bb184b contains a segmentation violation via the function gf_sm_load_init_swf at scene_manager/swf_parse.c
5.5
Medium
CVE-2022-47087 2023-01-04 23h00 +00:00 GPAC MP4box 2.1-DEV-rev574-g9d5bb184b has a Buffer overflow in gf_vvc_read_pps_bs_internal function of media_tools/av_parsers.c
7.8
High
CVE-2022-47088 2023-01-04 23h00 +00:00 GPAC MP4box 2.1-DEV-rev574-g9d5bb184b is vulnerable to Buffer Overflow.
7.8
High
CVE-2022-47089 2023-01-04 23h00 +00:00 GPAC MP4box 2.1-DEV-rev574-g9d5bb184b is vulnerable to Buffer Overflow via gf_vvc_read_sps_bs_internal function of media_tools/av_parsers.c
7.8
High
CVE-2022-47091 2023-01-04 23h00 +00:00 GPAC MP4box 2.1-DEV-rev574-g9d5bb184b is vulnerable to Buffer Overflow in gf_text_process_sub function of filters/load_text.c
7.8
High
CVE-2022-47092 2023-01-04 23h00 +00:00 GPAC MP4box 2.1-DEV-rev574-g9d5bb184b is contains an Integer overflow vulnerability in gf_hevc_read_sps_bs_internal function of media_tools/av_parsers.c:8316
7.1
High
CVE-2022-47093 2023-01-04 23h00 +00:00 GPAC MP4box 2.1-DEV-rev574-g9d5bb184b is vulnerable to heap use-after-free via filters/dmx_m2ts.c:470 in m2tsdmx_declare_pid
7.8
High
CVE-2022-47094 2023-01-04 23h00 +00:00 GPAC MP4box 2.1-DEV-rev574-g9d5bb184b is vulnerable to Null pointer dereference via filters/dmx_m2ts.c:343 in m2tsdmx_declare_pid
7.8
High
CVE-2022-47095 2023-01-04 23h00 +00:00 GPAC MP4box 2.1-DEV-rev574-g9d5bb184b is vulnerable to Buffer overflow in hevc_parse_vps_extension function of media_tools/av_parsers.c
7.8
High
CVE-2022-47653 2023-01-04 23h00 +00:00 GPAC MP4box 2.1-DEV-rev593-g007bf61a0 is vulnerable to Buffer Overflow in eac3_update_channels function of media_tools/av_parsers.c:9113
7.8
High
CVE-2022-47654 2023-01-04 23h00 +00:00 GPAC MP4box 2.1-DEV-rev593-g007bf61a0 is vulnerable to Buffer Overflow in gf_hevc_read_sps_bs_internal function of media_tools/av_parsers.c:8261
7.8
High
CVE-2022-47656 2023-01-04 23h00 +00:00 GPAC MP4box 2.1-DEV-rev617-g85ce76efd is vulnerable to Buffer Overflow in gf_hevc_read_sps_bs_internal function of media_tools/av_parsers.c:8273
7.8
High
CVE-2022-47657 2023-01-04 23h00 +00:00 GPAC MP4Box 2.1-DEV-rev644-g5c4df2a67 is vulnerable to buffer overflow in function hevc_parse_vps_extension of media_tools/av_parsers.c:7662
7.8
High
CVE-2022-47658 2023-01-04 23h00 +00:00 GPAC MP4Box 2.1-DEV-rev644-g5c4df2a67 is vulnerable to buffer overflow in function gf_hevc_read_vps_bs_internal of media_tools/av_parsers.c:8039
7.8
High
CVE-2022-47659 2023-01-04 23h00 +00:00 GPAC MP4box 2.1-DEV-rev644-g5c4df2a67 is vulnerable to Buffer Overflow in gf_bs_read_data
7.8
High
CVE-2022-47660 2023-01-04 23h00 +00:00 GPAC MP4Box 2.1-DEV-rev644-g5c4df2a67 is has an integer overflow in isomedia/isom_write.c
7.8
High
CVE-2022-47661 2023-01-04 23h00 +00:00 GPAC MP4Box 2.1-DEV-rev649-ga8f438d20 is vulnerable to Buffer Overflow via media_tools/av_parsers.c:4988 in gf_media_nalu_add_emulation_bytes
7.8
High
CVE-2022-47662 2023-01-04 23h00 +00:00 GPAC MP4Box 2.1-DEV-rev649-ga8f438d20 has a segment fault (/stack overflow) due to infinite recursion in Media_GetSample isomedia/media.c:662
5.5
Medium
CVE-2022-47663 2023-01-04 23h00 +00:00 GPAC MP4box 2.1-DEV-rev649-ga8f438d20 is vulnerable to buffer overflow in h263dmx_process filters/reframe_h263.c:609
7.8
High
CVE-2022-4202 2022-11-28 23h00 +00:00 A vulnerability, which was classified as problematic, was found in GPAC 2.1-DEV-rev490-g68064e101-master. Affected is the function lsr_translate_coords of the file laser/lsr_dec.c. The manipulation leads to integer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The name of the patch is b3d821c4ae9ba62b3a194d9dcb5e99f17bd56908. It is recommended to apply a patch to fix this issue. VDB-214518 is the identifier assigned to this vulnerability.
8.8
High
CVE-2022-45202 2022-11-28 23h00 +00:00 GPAC v2.1-DEV-rev428-gcb8ae46c8-master was discovered to contain a stack overflow via the function dimC_box_read at isomedia/box_code_3gpp.c.
7.8
High
CVE-2022-45204 2022-11-28 23h00 +00:00 GPAC v2.1-DEV-rev428-gcb8ae46c8-master was discovered to contain a memory leak via the function dimC_box_read at isomedia/box_code_3gpp.c.
5.5
Medium
CVE-2022-45343 2022-11-28 23h00 +00:00 GPAC v2.1-DEV-rev478-g696e6f868-master was discovered to contain a heap use-after-free via the Q_IsTypeOn function at /gpac/src/bifs/unquantize.c.
7.8
High
CVE-2022-3957 2022-11-10 23h00 +00:00 A vulnerability classified as problematic was found in GPAC. Affected by this vulnerability is the function svg_parse_preserveaspectratio of the file scenegraph/svg_attributes.c of the component SVG Parser. The manipulation leads to memory leak. The attack can be launched remotely. The name of the patch is 2191e66aa7df750e8ef01781b1930bea87b713bb. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-213463.
6.5
Medium
CVE-2022-43254 2022-11-01 23h00 +00:00 GPAC v2.1-DEV-rev368-gfd054169b-master was discovered to contain a memory leak via the component gf_list_new at utils/list.c.
5.5
Medium
CVE-2022-43255 2022-11-01 23h00 +00:00 GPAC v2.1-DEV-rev368-gfd054169b-master was discovered to contain a memory leak via the component gf_odf_new_iod at odf/odf_code.c.
5.5
Medium
CVE-2022-43039 2022-10-18 22h00 +00:00 GPAC 2.1-DEV-rev368-gfd054169b-master was discovered to contain a segmentation violation via the function gf_isom_meta_restore_items_ref at /isomedia/meta.c.
5.5
Medium
CVE-2022-43040 2022-10-18 22h00 +00:00 GPAC 2.1-DEV-rev368-gfd054169b-master was discovered to contain a heap buffer overflow via the function gf_isom_box_dump_start_ex at /isomedia/box_funcs.c.
7.8
High
CVE-2022-43042 2022-10-18 22h00 +00:00 GPAC 2.1-DEV-rev368-gfd054169b-master was discovered to contain a heap buffer overflow via the function FixSDTPInTRAF at isomedia/isom_intern.c.
7.8
High
CVE-2022-43043 2022-10-18 22h00 +00:00 GPAC 2.1-DEV-rev368-gfd054169b-master was discovered to contain a segmentation violation via the function BD_CheckSFTimeOffset at /bifs/field_decode.c.
5.5
Medium
CVE-2022-43044 2022-10-18 22h00 +00:00 GPAC 2.1-DEV-rev368-gfd054169b-master was discovered to contain a segmentation violation via the function gf_isom_get_meta_item_info at /isomedia/meta.c.
5.5
Medium
CVE-2022-43045 2022-10-18 22h00 +00:00 GPAC 2.1-DEV-rev368-gfd054169b-master was discovered to contain a segmentation violation via the function gf_dump_vrml_sffield at /scene_manager/scene_dump.c.
5.5
Medium
CVE-2022-3178 2022-09-12 14h30 +00:00 Buffer Over-read in GitHub repository gpac/gpac prior to 2.1.0-DEV.
7.8
High
CVE-2022-38530 2022-09-05 22h00 +00:00 GPAC v2.1-DEV-rev232-gfcaa01ebb-master was discovered to contain a stack overflow when processing ISOM_IOD.
7.8
High
CVE-2022-36190 2022-08-16 22h00 +00:00 GPAC mp4box 2.1-DEV-revUNKNOWN-master has a use-after-free vulnerability in function gf_isom_dovi_config_get. This vulnerability was fixed in commit fef6242.
9.8
Critical
CVE-2022-36191 2022-08-16 22h00 +00:00 A heap-buffer-overflow had occurred in function gf_isom_dovi_config_get of isomedia/avc_ext.c:2490, as demonstrated by MP4Box. This vulnerability was fixed in commit fef6242.
5.5
Medium
CVE-2022-1795 2022-05-17 22h00 +00:00 Use After Free in GitHub repository gpac/gpac prior to v2.1.0-DEV.
9.8
Critical
CVE-2022-29340 2022-05-05 10h46 +00:00 GPAC 2.1-DEV-rev87-g053aae8-master. has a Null Pointer Dereference vulnerability in gf_isom_parse_movie_boxes_internal due to improper return value handling of GF_SKIP_BOX, which causes a Denial of Service. This vulnerability was fixed in commit 37592ad.
7.5
High
CVE-2022-29339 2022-05-05 10h44 +00:00 In GPAC 2.1-DEV-rev87-g053aae8-master, function BS_ReadByte() in utils/bitstream.c has a failed assertion, which causes a Denial of Service. This vulnerability was fixed in commit 9ea93a2.
7.5
High