Debian Gpac vulnerabilities
200 known vulnerabilities affecting debian/gpac.
Total CVEs
200
CISA KEV
0
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL7HIGH80MEDIUM108LOW5
Vulnerabilities
Page 1 of 10
CVE-2021-4043P4MEDIUMCVSS 5.5Exploitedfixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2021
CVE-2021-4043 [MEDIUM] CVE-2021-4043: gpac - NULL Pointer Dereference in GitHub repository gpac/gpac prior to 1.1.0.
NULL Pointer Dereference in GitHub repository gpac/gpac prior to 1.1.0.
Scope: local
bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2021-21843P3HIGHCVSS 8.8fixed in gpac 1.0.1+dfsg1-4+deb11u1 (bullseye)2021
CVE-2021-21843 [HIGH] CVE-2021-21843: gpac - Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 de...
Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an integer overflow due to unchecked arithmetic resulting in a heap-based buffer overflow that causes memory corruption. After validating the number of ranges, at [41] the
debian
CVE-2021-21839P3HIGHCVSS 8.8fixed in gpac 1.0.1+dfsg1-4+deb11u1 (bullseye)2021
CVE-2021-21839 [HIGH] CVE-2021-21839: gpac - Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 de...
Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an integer overflow due to unchecked arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user to open a video to
debian
CVE-2021-21838P3HIGHCVSS 8.8fixed in gpac 1.0.1+dfsg1-4+deb11u1 (bullseye)2021
CVE-2021-21838 [HIGH] CVE-2021-21838: gpac - Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 de...
Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an integer overflow due to unchecked arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user to open a video to
debian
CVE-2021-21845P3HIGHCVSS 8.8fixed in gpac 1.0.1+dfsg1-4+deb11u1 (bullseye)2021
CVE-2021-21845 [HIGH] CVE-2021-21845: gpac - Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 de...
Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input in “stsc” decoder can cause an integer overflow due to unchecked arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user
debian
CVE-2021-21846P3HIGHCVSS 8.8fixed in gpac 1.0.1+dfsg1-4+deb11u1 (bullseye)2021
CVE-2021-21846 [HIGH] CVE-2021-21846: gpac - Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 de...
Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input in “stsz” decoder can cause an integer overflow due to unchecked arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user
debian
CVE-2021-21837P3HIGHCVSS 8.8fixed in gpac 1.0.1+dfsg1-4+deb11u1 (bullseye)2021
CVE-2021-21837 [HIGH] CVE-2021-21837: gpac - Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 de...
Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an integer overflow due to unchecked arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user to open a video to
debian
CVE-2021-21852P3HIGHCVSS 8.8fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2021
CVE-2021-21852 [HIGH] CVE-2021-21852: ccextractor - Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 de...
Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input at “stss” decoder can cause an integer overflow due to unchecked arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince
debian
CVE-2021-21847P3HIGHCVSS 8.8fixed in gpac 1.0.1+dfsg1-4+deb11u1 (bullseye)2021
CVE-2021-21847 [HIGH] CVE-2021-21847: gpac - Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 de...
Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input in “stts” decoder can cause an integer overflow due to unchecked arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user
debian
CVE-2021-21844P3HIGHCVSS 8.8fixed in gpac 1.0.1+dfsg1-4+deb11u1 (bullseye)2021
CVE-2021-21844 [HIGH] CVE-2021-21844: gpac - Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 de...
Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input when encountering an atom using the “stco” FOURCC code, can cause an integer overflow due to unchecked arithmetic resulting in a heap-based buffer overflow that causes memory corrup
debian
CVE-2021-21848P3HIGHCVSS 8.8fixed in gpac 1.0.1+dfsg1-4+deb11u1 (bullseye)2021
CVE-2021-21848 [HIGH] CVE-2021-21848: gpac - An exploitable integer overflow vulnerability exists within the MPEG-4 decoding ...
An exploitable integer overflow vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. The library will actually reuse the parser for atoms with the “stsz” FOURCC code when parsing atoms that use the “stz2” FOURCC code and can cause an integer overflow due to unchecked arithmetic resulting in a heap-based b
debian
CVE-2021-21858P3HIGHCVSS 8.8fixed in gpac 1.0.1+dfsg1-4+deb11u1 (bullseye)2021
CVE-2021-21858 [HIGH] CVE-2021-21858: gpac - Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 de...
Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an integer overflow due to unchecked addition arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user to open a
debian
CVE-2021-21853P3HIGHCVSS 8.8fixed in gpac 1.0.1+dfsg1-4+deb11u1 (bullseye)2021
CVE-2021-21853 [HIGH] CVE-2021-21853: gpac - Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 de...
Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an integer overflow due to unchecked addition arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user to open a
debian
CVE-2021-21855P3HIGHCVSS 8.8fixed in gpac 1.0.1+dfsg1-4+deb11u1 (bullseye)2021
CVE-2021-21855 [HIGH] CVE-2021-21855: gpac - Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 de...
Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an integer overflow due to unchecked addition arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user to open a
debian
CVE-2021-21857P3HIGHCVSS 8.8fixed in gpac 1.0.1+dfsg1-4+deb11u1 (bullseye)2021
CVE-2021-21857 [HIGH] CVE-2021-21857: gpac - Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 de...
Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an integer overflow due to unchecked addition arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user to open a
debian
CVE-2021-21854P3HIGHCVSS 8.8fixed in gpac 1.0.1+dfsg1-4+deb11u1 (bullseye)2021
CVE-2021-21854 [HIGH] CVE-2021-21854: gpac - Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 de...
Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an integer overflow due to unchecked addition arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user to open a
debian
CVE-2021-21841P3HIGHCVSS 8.8fixed in gpac 1.0.1+dfsg1-4+deb11u1 (bullseye)2021
CVE-2021-21841 [HIGH] CVE-2021-21841: gpac - An exploitable integer overflow vulnerability exists within the MPEG-4 decoding ...
An exploitable integer overflow vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input when reading an atom using the 'sbgp' FOURCC code can cause an integer overflow due to unchecked arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An atta
debian
CVE-2021-21842P3HIGHCVSS 8.8fixed in gpac 1.0.1+dfsg1-4+deb11u1 (bullseye)2021
CVE-2021-21842 [HIGH] CVE-2021-21842: gpac - An exploitable integer overflow vulnerability exists within the MPEG-4 decoding ...
An exploitable integer overflow vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an integer overflow when processing an atom using the 'ssix' FOURCC code, due to unchecked arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An
debian
CVE-2021-21834P3HIGHCVSS 8.8fixed in gpac 1.0.1+dfsg1-4+deb11u1 (bullseye)2021
CVE-2021-21834 [HIGH] CVE-2021-21834: gpac - An exploitable integer overflow vulnerability exists within the MPEG-4 decoding ...
An exploitable integer overflow vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input when decoding the atom for the “co64” FOURCC can cause an integer overflow due to unchecked arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker
debian
CVE-2021-21836P3HIGHCVSS 8.8fixed in gpac 1.0.1+dfsg1-4+deb11u1 (bullseye)2021
CVE-2021-21836 [HIGH] CVE-2021-21836: gpac - An exploitable integer overflow vulnerability exists within the MPEG-4 decoding ...
An exploitable integer overflow vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input using the “ctts” FOURCC code can cause an integer overflow due to unchecked arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a u
debian
1 / 10Next →