Debian Gpac vulnerabilities
200 known vulnerabilities affecting debian/gpac.
Total CVEs
200
CISA KEV
0
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL7HIGH80MEDIUM108LOW5
Vulnerabilities
Page 9 of 10
CVE-2020-22674P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-2 (bullseye)2020
CVE-2020-22674 [MEDIUM] CVE-2020-22674: gpac - An issue was discovered in gpac 0.8.0. An invalid memory dereference exists in t...
An issue was discovered in gpac 0.8.0. An invalid memory dereference exists in the function FixTrackID located in isom_intern.c, which allows attackers to cause a denial of service (DoS) via a crafted input.
Scope: local
bullseye: resolved (fixed in 1.0.1+dfsg1-2)
debian
CVE-2021-45763P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2021
CVE-2021-45763 [MEDIUM] CVE-2021-45763: gpac - GPAC v1.1.0 was discovered to contain an invalid call in the function gf_node_ch...
GPAC v1.1.0 was discovered to contain an invalid call in the function gf_node_changed(). This vulnerability can lead to a Denial of Service (DoS).
Scope: local
bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2021-45767P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2021
CVE-2021-45767 [MEDIUM] CVE-2021-45767: gpac - GPAC 1.1.0 was discovered to contain an invalid memory address dereference via t...
GPAC 1.1.0 was discovered to contain an invalid memory address dereference via the function lsr_read_id(). This vulnerability can lead to a Denial of Service (DoS).
Scope: local
bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2021-45764P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2021
CVE-2021-45764 [MEDIUM] CVE-2021-45764: gpac - GPAC v1.1.0 was discovered to contain an invalid memory address dereference via ...
GPAC v1.1.0 was discovered to contain an invalid memory address dereference via the function shift_chunk_offsets.isra().
Scope: local
bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2020-25427P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-2 (bullseye)2020
CVE-2020-25427 [MEDIUM] CVE-2020-25427: gpac - A Null pointer dereference vulnerability exits in MP4Box - GPAC version 0.8.0-re...
A Null pointer dereference vulnerability exits in MP4Box - GPAC version 0.8.0-rev177-g51a8ef874-master via the gf_isom_get_track_id function, which causes a denial of service.
Scope: local
bullseye: resolved (fixed in 1.0.1+dfsg1-2)
debian
CVE-2022-3222P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2022
CVE-2022-3222 [MEDIUM] CVE-2022-3222: gpac - Uncontrolled Recursion in GitHub repository gpac/gpac prior to 2.1.0-DEV.
Uncontrolled Recursion in GitHub repository gpac/gpac prior to 2.1.0-DEV.
Scope: local
bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2021-46040P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2021
CVE-2021-46040 [MEDIUM] CVE-2021-46040: gpac - A Pointer Dereference Vulnerabilty exists in GPAC 1.0.1 via the finplace_shift_m...
A Pointer Dereference Vulnerabilty exists in GPAC 1.0.1 via the finplace_shift_moov_meta_offsets function, which causes a Denial of Servie (context-dependent).
Scope: local
bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2021-46038P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2021
CVE-2021-46038 [MEDIUM] CVE-2021-46038: gpac - A Pointer Dereference vulnerability exists in GPAC 1.0.1 in unlink_chunk.isra, w...
A Pointer Dereference vulnerability exists in GPAC 1.0.1 in unlink_chunk.isra, which causes a Denial of Service (context-dependent).
Scope: local
bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2021-45291P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2021
CVE-2021-45291 [MEDIUM] CVE-2021-45291: gpac - The gf_dump_setup function in GPAC 1.0.1 allows malicoius users to cause a denia...
The gf_dump_setup function in GPAC 1.0.1 allows malicoius users to cause a denial of service (Invalid memory address dereference) via a crafted file in the MP4Box command.
Scope: local
bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2021-45267P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2021
CVE-2021-45267 [MEDIUM] CVE-2021-45267: gpac - An invalid memory address dereference vulnerability exists in gpac 1.1.0 via the...
An invalid memory address dereference vulnerability exists in gpac 1.1.0 via the svg_node_start function, which causes a segmentation fault and application crash.
Scope: local
bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2021-46049P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2021
CVE-2021-46049 [MEDIUM] CVE-2021-46049: gpac - A Pointer Dereference Vulnerability exists in GPAC 1.0.1 via the gf_fileio_check...
A Pointer Dereference Vulnerability exists in GPAC 1.0.1 via the gf_fileio_check function, which could cause a Denial of Service.
Scope: local
bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2021-46046P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2021
CVE-2021-46046 [MEDIUM] CVE-2021-46046: gpac - A Pointer Derefernce Vulnerbility exists GPAC 1.0.1 the gf_isom_box_size functio...
A Pointer Derefernce Vulnerbility exists GPAC 1.0.1 the gf_isom_box_size function, which could cause a Denial of Service (context-dependent).
Scope: local
bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2021-46039P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2021
CVE-2021-46039 [MEDIUM] CVE-2021-46039: gpac - A Pointer Dereference Vulnerabilty exists in GPAC 1.0.1 via the shift_chunk_offs...
A Pointer Dereference Vulnerabilty exists in GPAC 1.0.1 via the shift_chunk_offsets.part function, which causes a Denial of Service (context-dependent).
Scope: local
bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2021-46043P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2021
CVE-2021-46043 [MEDIUM] CVE-2021-46043: gpac - A Pointer Dereference Vulnerability exits in GPAC 1.0.1 in the gf_list_count fun...
A Pointer Dereference Vulnerability exits in GPAC 1.0.1 in the gf_list_count function, which causes a Denial of Service.
Scope: local
bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2021-46051P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2021
CVE-2021-46051 [MEDIUM] CVE-2021-46051: gpac - A Pointer Dereference Vulnerability exists in GPAC 1.0.1 via the Media_IsSelfCon...
A Pointer Dereference Vulnerability exists in GPAC 1.0.1 via the Media_IsSelfContained function, which could cause a Denial of Service. .
Scope: local
bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2021-45263P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2021
CVE-2021-45263 [MEDIUM] CVE-2021-45263: gpac - An invalid free vulnerability exists in gpac 1.1.0 via the gf_svg_delete_attribu...
An invalid free vulnerability exists in gpac 1.1.0 via the gf_svg_delete_attribute_value function, which causes a segmentation fault and application crash.
Scope: local
bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2021-45262P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2021
CVE-2021-45262 [MEDIUM] CVE-2021-45262: gpac - An invalid free vulnerability exists in gpac 1.1.0 via the gf_sg_command_del fun...
An invalid free vulnerability exists in gpac 1.1.0 via the gf_sg_command_del function, which causes a segmentation fault and application crash.
Scope: local
bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2021-46044P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2021
CVE-2021-46044 [MEDIUM] CVE-2021-46044: gpac - A Pointer Dereference Vulnerabilty exists in GPAC 1.0.1via ShiftMetaOffset.isra,...
A Pointer Dereference Vulnerabilty exists in GPAC 1.0.1via ShiftMetaOffset.isra, which causes a Denial of Service (context-dependent).
Scope: local
bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2021-40944P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2021
CVE-2021-40944 [MEDIUM] CVE-2021-40944: gpac - In GPAC MP4Box 1.1.0, there is a Null pointer reference in the function gf_filte...
In GPAC MP4Box 1.1.0, there is a Null pointer reference in the function gf_filter_pid_get_packet function in src/filter_core/filter_pid.c:5394, as demonstrated by GPAC. This can cause a denial of service (DOS).
Scope: local
bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian
CVE-2021-40608P4MEDIUMCVSS 5.5fixed in gpac 1.0.1+dfsg1-4+deb11u2 (bullseye)2021
CVE-2021-40608 [MEDIUM] CVE-2021-40608: gpac - The gf_hinter_track_finalize function in GPAC 1.0.1 allows attackers to cause a ...
The gf_hinter_track_finalize function in GPAC 1.0.1 allows attackers to cause a denial of service via a crafted file in the MP4Box command.
Scope: local
bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
debian