Debian Gpac vulnerabilities
200 known vulnerabilities affecting debian/gpac.
Total CVEs
200
CISA KEV
0
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL7HIGH80MEDIUM108LOW5
Vulnerabilities
Page 10 of 10
CVE-2021-40609P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2021
CVE-2021-40609 [MEDIUM] CVE-2021-40609: gpac - The GetHintFormat function in GPAC 1.0.1 allows attackers to cause a denial of s...
The GetHintFormat function in GPAC 1.0.1 allows attackers to cause a denial of service via a crafted file in the MP4Box command.
Scope: local
bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2021-40606P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2021
CVE-2021-40606 [MEDIUM] CVE-2021-40606: gpac - The gf_bs_write_data function in GPAC 1.0.1 allows attackers to cause a denial o...
The gf_bs_write_data function in GPAC 1.0.1 allows attackers to cause a denial of service via a crafted file in the MP4Box command.
Scope: local
bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2023-0818P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2023
CVE-2023-0818 [MEDIUM] CVE-2023-0818: gpac - Off-by-one Error in GitHub repository gpac/gpac prior to v2.3.0-DEV.
Off-by-one Error in GitHub repository gpac/gpac prior to v2.3.0-DEV.
Scope: local
bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2021-31260P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-4 (bullseye)2021
CVE-2021-31260 [MEDIUM] CVE-2021-31260: ccextractor - The MergeTrack function in GPAC 1.0.1 allows attackers to cause a denial of serv...
The MergeTrack function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.
Scope: local
bullseye: open
debian
CVE-2021-31262P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-4 (bullseye)2021
CVE-2021-31262 [MEDIUM] CVE-2021-31262: gpac - The AV1_DuplicateConfig function in GPAC 1.0.1 allows attackers to cause a denia...
The AV1_DuplicateConfig function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.
Scope: local
bullseye: resolved (fixed in 1.0.1+dfsg1-4)
debian
CVE-2021-31257P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-4 (bullseye)2021
CVE-2021-31257 [MEDIUM] CVE-2021-31257: gpac - The HintFile function in GPAC 1.0.1 allows attackers to cause a denial of servic...
The HintFile function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.
Scope: local
bullseye: resolved (fixed in 1.0.1+dfsg1-4)
debian
CVE-2019-20632P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-2 (bullseye)2019
CVE-2019-20632 [MEDIUM] CVE-2019-20632: gpac - An issue was discovered in libgpac.a in GPAC before 0.8.0, as demonstrated by MP...
An issue was discovered in libgpac.a in GPAC before 0.8.0, as demonstrated by MP4Box. It contains an invalid pointer dereference in gf_odf_delete_descriptor in odf/desc_private.c that can cause a denial of service via a crafted MP4 file.
Scope: local
bullseye: resolved (fixed in 1.0.1+dfsg1-2)
debian
CVE-2020-23932P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-2 (bullseye)2020
CVE-2020-23932 [MEDIUM] CVE-2020-23932: gpac - An issue was discovered in gpac before 1.0.1. A NULL pointer dereference exists ...
An issue was discovered in gpac before 1.0.1. A NULL pointer dereference exists in the function dump_isom_sdp located in filedump.c. It allows an attacker to cause Denial of Service.
Scope: local
bullseye: resolved (fixed in 1.0.1+dfsg1-2)
debian
CVE-2020-22679P4LOWCVSS 5.5fixed in gpac 1.0.1+dfsg1-2 (bullseye)2020
CVE-2020-22679 [MEDIUM] CVE-2020-22679: gpac - Memory leak in the sgpd_parse_entry function in MP4Box in gpac 0.8.0 allows atta...
Memory leak in the sgpd_parse_entry function in MP4Box in gpac 0.8.0 allows attackers to cause a denial of service (DoS) via a crafted input.
Scope: local
bullseye: resolved (fixed in 1.0.1+dfsg1-2)
debian
CVE-2020-22673P4LOWCVSS 5.5fixed in gpac 1.0.1+dfsg1-2 (bullseye)2020
CVE-2020-22673 [MEDIUM] CVE-2020-22673: gpac - Memory leak in the senc_Parse function in MP4Box in gpac 0.8.0 allows attackers ...
Memory leak in the senc_Parse function in MP4Box in gpac 0.8.0 allows attackers to cause a denial of service (DoS) via a crafted input.
Scope: local
bullseye: resolved (fixed in 1.0.1+dfsg1-2)
debian
CVE-2019-20631P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-2 (bullseye)2019
CVE-2019-20631 [MEDIUM] CVE-2019-20631: gpac - An issue was discovered in libgpac.a in GPAC before 0.8.0, as demonstrated by MP...
An issue was discovered in libgpac.a in GPAC before 0.8.0, as demonstrated by MP4Box. It contains an invalid pointer dereference in gf_list_count in utils/list.c that can cause a denial of service via a crafted MP4 file.
Scope: local
bullseye: resolved (fixed in 1.0.1+dfsg1-2)
debian
CVE-2020-23930P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-2 (bullseye)2020
CVE-2020-23930 [MEDIUM] CVE-2020-23930: gpac - An issue was discovered in gpac through 20200801. A NULL pointer dereference exi...
An issue was discovered in gpac through 20200801. A NULL pointer dereference exists in the function nhmldump_send_header located in write_nhml.c. It allows an attacker to cause Denial of Service.
Scope: local
bullseye: resolved (fixed in 1.0.1+dfsg1-2)
debian
CVE-2020-22352P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-2 (bullseye)2020
CVE-2020-22352 [MEDIUM] CVE-2020-22352: gpac - The gf_dash_segmenter_probe_input function in GPAC v0.8 allows attackers to caus...
The gf_dash_segmenter_probe_input function in GPAC v0.8 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.
Scope: local
bullseye: resolved (fixed in 1.0.1+dfsg1-2)
debian
CVE-2021-32270P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-2 (bullseye)2021
CVE-2021-32270 [MEDIUM] CVE-2021-32270: gpac - An issue was discovered in gpac through 20200801. A NULL pointer dereference exi...
An issue was discovered in gpac through 20200801. A NULL pointer dereference exists in the function vwid_box_del located in box_code_base.c. It allows an attacker to cause Denial of Service.
Scope: local
bullseye: resolved (fixed in 1.0.1+dfsg1-2)
debian
CVE-2021-32269P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-2 (bullseye)2021
CVE-2021-32269 [MEDIUM] CVE-2021-32269: gpac - An issue was discovered in gpac through 20200801. A NULL pointer dereference exi...
An issue was discovered in gpac through 20200801. A NULL pointer dereference exists in the function ilst_item_box_dump located in box_dump.c. It allows an attacker to cause Denial of Service.
Scope: local
bullseye: resolved (fixed in 1.0.1+dfsg1-2)
debian
CVE-2021-46042P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2021
CVE-2021-46042 [MEDIUM] CVE-2021-46042: gpac - A Pointer Dereference Vulnerability exists in GPAC 1.0.1 via the _fseeko functio...
A Pointer Dereference Vulnerability exists in GPAC 1.0.1 via the _fseeko function, which causes a Denial of Service.
Scope: local
bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2021-46045P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2021
CVE-2021-46045 [MEDIUM] CVE-2021-46045: gpac - GPAC 1.0.1 is affected by: Abort failed. The impact is: cause a denial of servic...
GPAC 1.0.1 is affected by: Abort failed. The impact is: cause a denial of service (context-dependent).
Scope: local
bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2021-45292P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2021
CVE-2021-45292 [MEDIUM] CVE-2021-45292: gpac - The gf_isom_hint_rtp_read function in GPAC 1.0.1 allows attackers to cause a den...
The gf_isom_hint_rtp_read function in GPAC 1.0.1 allows attackers to cause a denial of service (Invalid memory address dereference) via a crafted file in the MP4Box command.
Scope: local
bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2022-43255P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2022
CVE-2022-43255 [MEDIUM] CVE-2022-43255: gpac - GPAC v2.1-DEV-rev368-gfd054169b-master was discovered to contain a memory leak v...
GPAC v2.1-DEV-rev368-gfd054169b-master was discovered to contain a memory leak via the component gf_odf_new_iod at odf/odf_code.c.
Scope: local
bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2022-47086P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2022
CVE-2022-47086 [MEDIUM] CVE-2022-47086: gpac - GPAC MP4Box v2.1-DEV-rev574-g9d5bb184b contains a segmentation violation via the...
GPAC MP4Box v2.1-DEV-rev574-g9d5bb184b contains a segmentation violation via the function gf_sm_load_init_swf at scene_manager/swf_parse.c
Scope: local
bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
← Previous10 / 10