Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
483 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (0.9) | 0.16% | — | GpacAI | 14/9/2026 | 14/9/2026 | A flaw has been found in GPAC up to f1219cde. Affected by this vulnerability is the function gf_node_get_field_count of the file scenegraph/base_scenegraph.c of the component MP4Box. Executing a manipulation can lead to reachable assertion. It is possible to launch the attack on the local host. The exploit has been… | |
| Aplazada | Baja (1.9) | 0.17% | — | GpacAI | 14/9/2026 | 15/9/2026 | A vulnerability was detected in GPAC up to f1219cde. Affected is the function gf_node_unregister of the file scenegraph/base_scenegraph.c of the component MP4Box. Performing a manipulation results in reachable assertion. Attacking locally is a requirement. The exploit is now public and may be used. Upgrading to… | |
| Aplazada | Baja (1.9) | 0.17% | — | GpacAI | 14/9/2026 | 16/9/2026 | A security flaw has been discovered in GPAC up to f1219cde. Affected by this vulnerability is the function stbl_GetSampleInfos of the file isomedia/stbl_read.c of the component MP4Box. The manipulation results in reachable assertion. The attack must be initiated from a local position. The exploit has been released to… | |
| Aplazada | Baja (1.9) | 0.17% | — | GpacAI | 14/9/2026 | 14/9/2026 | A vulnerability was identified in GPAC up to f1219cde. Affected is the function gf_sm_dump_command_list of the file scene_manager/scene_dump.c of the component MP4Box. The manipulation leads to reachable assertion. The attack must be carried out locally. The exploit is publicly available and might be used. Upgrading… | |
| Aplazada | Baja (1.9) | 0.17% | — | GpacAIGpac Mp4boxAI | 14/9/2026 | 15/9/2026 | A vulnerability was determined in GPAC up to f1219cde. This impacts the function xmt_parse_element of the file scene_manager/loader_xmt.c of the component MP4Box. Executing a manipulation can lead to reachable assertion. The attack is restricted to local execution. The exploit has been publicly disclosed and may be… | |
| Aplazada | Baja (1.9) | 0.17% | — | GpacAI | 14/9/2026 | 15/9/2026 | A vulnerability was found in GPAC up to f1219cde. This affects the function gf_svg_attributes_copy of the file scenegraph/svg_attributes.c of the component MP4Box. Performing a manipulation results in buffer over-read. The attack is only possible with local access. The exploit has been made public and could be used.… | |
| Aplazada | Baja (1.9) | 0.17% | — | GpacAI | 14/9/2026 | 14/9/2026 | A vulnerability has been found in GPAC up to f1219cde. The impacted element is an unknown function of the file scenegraph/vrml_tools.c of the component MP4Box. Such manipulation leads to null pointer dereference. The attack can only be performed from a local environment. The exploit has been disclosed to the public… | |
| Aplazada | Baja (1.9) | 0.17% | — | GpacAI | 13/9/2026 | 15/9/2026 | A flaw has been found in GPAC up to f1219cde. Affected by this issue is the function gf_list_count of the file utils/list.c of the component MP4Box. Executing a manipulation can lead to use after free. The attack is restricted to local execution. The exploit has been published and may be used. Upgrading to version… | |
| Aplazada | Baja (1.9) | 0.18% | — | GpacAI | 13/9/2026 | 15/9/2026 | A vulnerability was detected in GPAC up to f1219cde. Affected by this vulnerability is the function gf_node_get_field of the file scenegraph/base_scenegraph.c of the component MP4Box. Performing a manipulation results in heap-based buffer overflow. The attack is only possible with local access. The exploit is now… | |
| Aplazada | Baja (1.9) | 0.17% | — | GpacAI | 13/9/2026 | 14/9/2026 | A security vulnerability has been detected in GPAC up to f1219cde. Affected is the function gf_node_list_add_child of the file scenegraph/base_scenegraph.c of the component MP4Box. Such manipulation leads to null pointer dereference. The attack can only be performed from a local environment. The exploit has been… | |
| Aplazada | Baja (1.9) | 0.17% | — | GpacAI | 13/9/2026 | 16/9/2026 | A vulnerability was identified in GPAC up to f1219cde. The impacted element is the function gf_sg_mfurl_del of the file scenegraph/vrml_tools.c of the component MP4Box. The manipulation leads to null pointer dereference. Local access is required to approach this attack. The exploit is publicly available and might be… | |
| Aplazada | Media (6.9) | 0.41% | — | Msgpack-javaAI | 12/9/2026 | 23/9/2026 | msgpack-java through 0.9.12 contains an integer overflow vulnerability in MessageUnpacker.skipValue() when processing MAP32 containers with large element counts. Attackers can supply a MAP32 element count at or above 0x40000000 that wraps when doubled, causing the parser cursor to desynchronize and attacker-controlled… | |
| Aplazada | Media (6.9) | 0.57% | — | Msgpack-javaAI | 12/9/2026 | 23/9/2026 | msgpack-java through 0.9.12 contains a stack overflow vulnerability in MessageUnpacker.unpackValue() that recursively deserializes arrays and maps without nesting depth limits. Attackers can craft payloads with deeply nested arrays to exhaust the deserializing thread's stack and trigger StackOverflowError, causing… | |
| Analizada | Media (6.5) | 0.54% | — | Gpac | 9/9/2026 | 15/9/2026 | An out-of-bounds read in the gf_dm_get_chunk_data function (src/utils/downloader.c) of GPAC v26.07.0 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request. Fixed in 2fd5a06ab226767900fd86edb5a1e8bfc1010640. | |
| Analizada | Media (6.5) | 0.54% | — | Gpac | 9/9/2026 | 15/9/2026 | An out-of-bounds read in the gf_dm_data_received function (downloader.c) of GPAC v26.07.0 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request. Fixed in 2fd5a06ab226767900fd86edb5a1e8bfc1010640. | |
| Analizada | Media (6.5) | 0.37% | — | Gpac | 9/9/2026 | 15/9/2026 | A divide-by-zero vulnerability in the gf_dash_get_timeline_duration function (src/media_tools/dash_client.c) of GPAC v26.07.0 allows attackers to cause a Denial of Service (DoS) via a crafted MPD SegmentTimeline. Fixed in 2fd5a06ab226767900fd86edb5a1e8bfc1010640. | |
| Pendiente de análisis | Media (6.2) | 0.16% | — | GpacAI | 9/9/2026 | 14/9/2026 | An issue in GPAC c2dee3aff638cd96f9617ac5b17dc2868cd90ef3 allows an attacker to cause a denial of service via the function gf_route_media_complete_object(). Fixed in 3c4e6c5b3e0c6fa9b16d55599701a08354538fab. | |
| Pendiente de análisis | Alta (8.4) | 0.22% | — | GpacAI | 9/9/2026 | 14/9/2026 | An issue in GPAC c2dee3aff638cd96f9617ac5b17dc2868cd90ef3 allows an attacker to execute arbitrary code via the src/media_tools/dvb_mpe.c, descriptorTime_slice_fec_identifier() and gf_m2ts_ipdatagram_reader() components. Fixed in 0e4093392e1f847c90d20e031e893cd942fef938. | |
| Pendiente de análisis | Alta (7.8) | 0.20% | — | GpacAI | 9/9/2026 | 10/9/2026 | Buffer Overflow vulnerability in GPAC c2dee3aff638cd96f9617ac5b17dc2868cd90ef3 allows an attacker to execute arbitrary code via the j2kdec_process() function. Fixed in 9a253a07fd3f6b48022bba74302bf39388dda859. | |
| Pendiente de análisis | Alta (8.4) | 0.21% | — | GpacAI | 9/9/2026 | 14/9/2026 | Buffer Overflow vulnerability in GPAC c2dee3aff638cd96f9617ac5b17dc2868cd90ef3 allows an attacker to execute arbitrary code via the nhntdmx_process() function. Fixed in fac50e6a12ac27ffabdd5d3080b51afcc44ad8d6. | |
| Pendiente de análisis | Alta (7.8) | 0.19% | — | GpacAI | 25/8/2026 | 9/9/2026 | Buffer Overflow vulnerability in gpac 31becc9e08b88e525a4a62013a4000de1c0f8fd9 allows an attacker to execute arbitrary code via the svgNameToImplementationName() function | |
| Aplazada | Media (5.8) | 0.16% | — | Msgpack-cAI | 20/8/2026 | 24/9/2026 | msgpack_unpacker_expand_buffer in src/unpack.c, reached through the public msgpack_unpacker_reserve_buffer API, computes its new buffer size using an unchecked size_t addition of the requested size and the amount already used. The doubling loop guards its own multiplication against overflow, but the addition in the… | |
| Analizada | Baja (2.1) | 0.23% | — | Msgpack Messagepack | 30/7/2026 | 5/8/2026 | MessagePack for Ruby is an implementation of the MessagePack binary serialization format. Prior to 1.8.2, MessagePack::Buffer#clear in ext/msgpack/buffer.c leaves rmem_last, rmem_end, and rmem_owner stale after _msgpack_buffer_shift_chunk returns an rmem page to the shared pool, allowing a subsequent Buffer#write and… | |
| Aplazada | Baja (1.9) | 0.16% | — | GpacAI | 9/7/2026 | 9/7/2026 | A vulnerability was determined in GPAC 26.03-DEV. This affects the function vobsub_read_idx of the file /src/media_tools/vobsub.c of the component MP4Box. Executing a manipulation of the argument num_langs can lead to out-of-bounds read. The attack needs to be launched locally. The exploit has been publicly disclosed… | |
| Aplazada | Media (5.5) | 0.17% | — | GpacAI | 7/7/2026 | 10/7/2026 | A NULL pointer dereference in smooth_parse_stream_index() in src/media_tools/mpd.c in GPAC master HEAD before commit b35c61f104b85fbb16520ac2838d5d2ef70845b5 allows attackers to cause a denial of service |