vciy

CVEs we hold for Gpac

Records whose assigning authority named Gpac as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-9572GPAC MP4Box media.c Media_GetSample memory leakn/a GPAC
CVE-2026-9567GPAC MP4Box isom_intern.c MergeFragment null pointer dereferencen/a GPAC
CVE-2026-93331GPAC RTP Depacketizer rtp_depacketizer.c gf_rtp_parse_ttxt out-of-boundsn/a GPAC
CVE-2026-92475GPAC downloader.c wait_for_header_and_parse out-of-boundsn/a GPAC
CVE-2026-92474GPAC Proto Link mpeg4_inline.c gf_inline_get_proto_lib use after freen/a GPAC
CVE-2026-92473GPAC BIFS commands.c gf_sg_command_del use after freen/a GPAC
CVE-2026-92472GPAC MP4Box base_scenegraph.c gf_node_deactivate_ex use after freen/a GPAC
CVE-2026-92399GPAC WebSocket rmt_ws.c rmt_client_handle_ws_frame heap-based overflown/a GPAC
CVE-2026-91091GPAC Node Insertion base_scenegraph.c gf_node_list_insert_child memory corruptionn/a GPAC
CVE-2026-91090GPAC base_scenegraph.c gf_node_activate_ex stack-based overflown/a GPAC
CVE-2026-91089GPAC base_scenegraph.c gf_node_get_name_and_id use after freen/a GPAC
CVE-2026-91088GPAC URL url.c gf_url_concatenate_ex heap-based overflown/a GPAC
CVE-2026-91087GPAC Compositor media_object.c gf_mo_get_od_id use after freen/a GPAC
CVE-2026-91086GPAC MPEG Video Reframer reframe_mpgvid.c mpgviddmx_process heap-based overflown/a GPAC
CVE-2026-90827GPAC MP4Box base_scenegraph.c gf_node_deactivate_ex use after freen/a GPAC
CVE-2026-90826GPAC MP4Box base_scenegraph.c gf_node_del out-of-boundsn/a GPAC
CVE-2026-90825GPAC MP4Box base_scenegraph.c gf_node_unregister use after freen/a GPAC
CVE-2026-90824GPAC MP4Box dom_events.c gf_sg_dom_event_bubble stack-based overflown/a GPAC
CVE-2026-90794GPAC MP4Box vrml_tools.c gf_sg_script_load use after freen/a GPAC
CVE-2026-90793GPAC MP4Box base_scenegraph.c gf_node_get_name use after freen/a GPAC
CVE-2026-90792GPAC MP4Box base_scenegraph.c gf_node_list_get_child null pointer dereferencen/a GPAC
CVE-2026-90791GPAC MP4Box base_scenegraph.c gf_node_unregister use after freen/a GPAC
CVE-2026-90687GPAC MP4Box base_scenegraph.c gf_node_changed_internal use after freen/a GPAC
CVE-2026-90686GPAC MP4Box loader_bt.c gf_bt_report memory corruptionn/a GPAC
CVE-2026-90685GPAC MP4Box lsr_dec.c lsr_exec_command_list assertionn/a GPAC
CVE-2026-90684GPAC MP4Box base_scenegraph.c gf_node_get_field_count assertionn/a GPAC
CVE-2026-90683GPAC MP4Box base_scenegraph.c gf_node_unregister assertionn/a GPAC
CVE-2026-90613GPAC MP4Box stbl_read.c stbl_GetSampleInfos assertionn/a GPAC
CVE-2026-90612GPAC MP4Box scene_dump.c gf_sm_dump_command_list assertionn/a GPAC
CVE-2026-90611GPAC MP4Box loader_xmt.c xmt_parse_element assertionn/a GPAC
CVE-2026-90610GPAC MP4Box svg_attributes.c gf_svg_attributes_copy buffer over-readn/a GPAC
CVE-2026-90609GPAC MP4Box vrml_tools.c null pointer dereferencen/a GPAC
CVE-2026-90578GPAC MP4Box list.c gf_list_count use after freen/a GPAC
CVE-2026-90577GPAC MP4Box base_scenegraph.c gf_node_get_field heap-based overflown/a GPAC
CVE-2026-90576GPAC MP4Box base_scenegraph.c gf_node_list_add_child null pointer dereferencen/a GPAC
CVE-2026-90573GPAC MP4Box vrml_tools.c gf_sg_mfurl_del null pointer dereferencen/a GPAC
CVE-2026-8124GPAC box_code_base.c sidx_box_read allocation of resourcesn/a GPAC
CVE-2026-7135GPAC MP4Box box_code_base.c elng_box_read out-of-boundsn/a GPAC
CVE-2026-4185GPAC MP4Box swf_parse.c swf_def_bits_jpeg stack-based overflown/a GPAC
CVE-2026-4016GPAC SVG Parser load_svg.c svgin_process out-of-bounds writen/a GPAC
CVE-2026-4015GPAC TeXML File load_text.c txtin_process_texml stack-based overflown/a GPAC
CVE-2026-33144GPAC MP4Box Heap Buffer Overflow Write in gf_xml_parse_bit_sequence_bs (NHML BS Parsing)gpac
CVE-2026-27821GPAC NHML Demuxer (dmx_nhml.c) Vulnerable to Stack Buffer Overflowgpac
CVE-2026-15185GPAC MP4Box vobsub.c vobsub_read_idx out-of-boundsn/a GPAC
CVE-2026-14801GPAC TeXML File load_text.c txtin_probe_duration divide by zeron/a GPAC
CVE-2026-14790GPAC Media File write_nhml.c nhmldump_send_frame null pointer dereferencen/a GPAC
CVE-2026-1418GPAC SRT Subtitle Import text_to_bifs.c gf_text_import_srt_bifs out-of-bounds writen/a GPAC
CVE-2026-1417GPAC filedump.c dump_isom_rtp null pointer dereferencen/a GPAC
CVE-2026-1416GPAC filedump.c DumpMovieInfo null pointer dereferencen/a GPAC
CVE-2026-1415GPAC media_export.c gf_media_export_webvtt_metadata null pointer dereferencen/a GPAC
CVE-2026-13523GPAC ISOBMFF base_encoding.c data amplificationn/a GPAC
CVE-2025-7797GPAC dash_client.c gf_dash_download_init_segment null pointer dereferencen/a GPAC
CVE-2025-15668GPAC MP4Box box_code_base.c sgpd_del_entry heap-based overflown/a GPAC
CVE-2025-15667GPAC MP4Box avc_ext.c gf_isom_nalu_sample_rewrite double freen/a GPAC
CVE-2024-6064GPAC MP4Box loader_xmt.c xmt_node_end use after freen/a GPAC
CVE-2024-6063GPAC MP4Box dmx_m2ts.c m2tsdmx_on_event null pointer dereferencen/a GPAC
CVE-2024-6062GPAC MP4Box load_text.c swf_svg_add_iso_sample null pointer dereferencen/a GPAC
CVE-2024-6061GPAC MP4Box isoffin_read.c isoffin_process infinite loopn/a GPAC
CVE-2024-0322Out-of-bounds Read in gpac/gpacgpac/gpac
CVE-2024-0321Stack-based Buffer Overflow in gpac/gpacgpac/gpac
CVE-2023-5998Out-of-bounds Read in gpac/gpacgpac/gpac
CVE-2023-5595Denial of Service in gpac/gpacgpac/gpac
CVE-2023-5586NULL Pointer Dereference in gpac/gpacgpac/gpac
CVE-2023-5520Out-of-bounds Read in gpac/gpacgpac/gpac
CVE-2023-5377Out-of-bounds Read in gpac/gpacgpac/gpac
CVE-2023-4778Out-of-bounds Read in gpac/gpacgpac/gpac
CVE-2023-4758Buffer Over-read in gpac/gpacgpac/gpac
CVE-2023-4756Stack-based Buffer Overflow in gpac/gpacgpac/gpac
CVE-2023-4755Use After Free in gpac/gpacgpac/gpac
CVE-2023-4754Out-of-bounds Write in gpac/gpacgpac/gpac
CVE-2023-4722Integer Overflow or Wraparound in gpac/gpacgpac/gpac
CVE-2023-4721Out-of-bounds Read in gpac/gpacgpac/gpac
CVE-2023-4720Floating Point Comparison with Incorrect Operator in gpac/gpacgpac/gpac
CVE-2023-4683NULL Pointer Dereference in gpac/gpacgpac/gpac
CVE-2023-4682Heap-based Buffer Overflow in gpac/gpacgpac/gpac
CVE-2023-4681NULL Pointer Dereference in gpac/gpacgpac/gpac
CVE-2023-4679Use After Free in gpac/gpacgpac/gpac
CVE-2023-4678Divide By Zero in gpac/gpacgpac/gpac
CVE-2023-3523Out-of-bounds Read in gpac/gpacgpac/gpac
CVE-2023-3291Heap-based Buffer Overflow in gpac/gpacgpac/gpac
CVE-2023-3013Unchecked Return Value in gpac/gpacgpac/gpac
CVE-2023-3012NULL Pointer Dereference in gpac/gpacgpac/gpac
CVE-2023-2840NULL Pointer Dereference in gpac/gpacgpac/gpac
CVE-2023-2839Divide By Zero in gpac/gpacgpac/gpac
CVE-2023-2838Out-of-bounds Read in gpac/gpacgpac/gpac
CVE-2023-2837Stack-based Buffer Overflow in gpac/gpacgpac/gpac
CVE-2023-1655Heap-based Buffer Overflow in gpac/gpacgpac/gpac
CVE-2023-1654Denial of Service in gpac/gpacgpac/gpac
CVE-2023-1452GPAC load_text.c buffer overflown/a GPAC
CVE-2023-1449GPAC av_parsers.c gf_av1_reset_state double freen/a GPAC
CVE-2023-1448GPAC mpegts.c gf_m2ts_process_sdt heap-based overflown/a GPAC
CVE-2023-0866Heap-based Buffer Overflow in gpac/gpacgpac/gpac
CVE-2023-0841GPAC reframe_mp3.c mp3_dmx_process heap-based overflown/a GPAC
CVE-2023-0819Heap-based Buffer Overflow in gpac/gpacgpac/gpac
CVE-2023-0818Off-by-one Error in gpac/gpacgpac/gpac
CVE-2023-0817Buffer Over-read in gpac/gpacgpac/gpac
CVE-2023-0770Stack-based Buffer Overflow in gpac/gpacgpac/gpac
CVE-2023-0760Heap-based Buffer Overflow in gpac/gpacgpac/gpac
CVE-2023-0358Use After Free in gpac/gpacgpac/gpac
CVE-2022-3222Uncontrolled Recursion in gpac/gpacgpac/gpac
CVE-2022-3178Buffer Over-read in gpac/gpacgpac/gpac
CVE-2022-2549NULL Pointer Dereference in gpac/gpacgpac/gpac
CVE-2022-2454Integer Overflow or Wraparound in gpac/gpacgpac/gpac
CVE-2022-2453Use After Free in gpac/gpacgpac/gpac
CVE-2022-1795Use After Free in gpac/gpacgpac/gpac
CVE-2022-1441no title heldn/a gpac
CVE-2022-1222Inf loop in gpac/gpacgpac/gpac
CVE-2022-1172Null Pointer Dereference Caused Segmentation Fault in gpac/gpacgpac/gpac
CVE-2022-1035Segmentation Fault caused by MP4Box -lsr in gpac/gpacgpac/gpac
CVE-2021-4043NULL Pointer Dereference in gpac/gpacgpac/gpac
CVE-2021-21862no title heldn/a GPAC
CVE-2021-21861no title heldn/a GPAC Project
CVE-2021-21860no title heldn/a GPAC Project
CVE-2021-21859no title heldn/a GPAC Project
CVE-2021-21858no title heldn/a GPAC
CVE-2021-21857no title heldn/a GPAC
CVE-2021-21856no title heldn/a GPAC
CVE-2021-21855no title heldn/a GPAC
CVE-2021-21854no title heldn/a GPAC
CVE-2021-21853no title heldn/a GPAC
CVE-2021-21852no title heldn/a GPAC"
CVE-2021-21851no title heldn/a GPAC"
CVE-2021-21850no title heldn/a GPAC Project
CVE-2021-21849no title heldn/a GPAC Project
CVE-2021-21848no title heldn/a GPAC Project
CVE-2021-21847no title heldn/a GPAC
CVE-2021-21846no title heldn/a GPAC
CVE-2021-21845no title heldn/a GPAC
CVE-2021-21844no title heldn/a GPAC
CVE-2021-21843no title heldn/a GPAC
CVE-2021-21842no title heldn/a GPAC Project
CVE-2021-21841no title heldn/a GPAC Project
CVE-2021-21840no title heldn/a GPAC Project
CVE-2021-21839no title heldn/a GPAC
CVE-2021-21838no title heldn/a GPAC
CVE-2021-21837no title heldn/a GPAC
CVE-2021-21836no title heldn/a GPAC Project
CVE-2021-21835no title heldn/a GPAC Project
CVE-2021-21834no title heldn/a GPAC Project

139 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.