Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
483 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.24% | — | Gpac | 15/6/2026 | 17/6/2026 | A NULL pointer dereference in the TrackWriter handling component (filters/mux_isom.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file. | |
| Analizada | Media (5.5) | 0.24% | — | Gpac | 15/6/2026 | 17/6/2026 | A NULL pointer dereference in the gf_isom_copy_sample_info function (isomedia/isom_write.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file. | |
| Analizada | Media (6.5) | 0.50% | — | Gpac | 15/6/2026 | 5/10/2026 | GPAC MP4Box v2.4 was discovered to contain a floating point exception in the avidmx_process function (isomedia/isom_write.c). | |
| Modificada | Media (6.5) | 0.34% | — | Gpac | 9/6/2026 | 23/7/2026 | A NULL pointer dereference in the ctts_box_write function (isomedia/box_code_base.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file. | |
| Analizada | Media (6.5) | 0.30% | — | Gpac | 9/6/2026 | 23/7/2026 | GPAC MP4Box v2.4 was discovered to contain a floating point exception in the gf_opus_parse_packet_header function (media_tools/av_parsers.c). bThis vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted MP4 file. | |
| Modificada | Alta (7.5) | 0.47% | — | Gpac | 9/6/2026 | 23/7/2026 | A NULL pointer dereference in the gf_odf_vvc_cfg_write_bs function (odf/descriptors.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file. | |
| Modificada | Media (5.5) | 0.19% | — | Gpac | 9/6/2026 | 23/7/2026 | A NULL pointer dereference in the gf_isom_get_user_data_count function (isomedia/isom_read.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file. | |
| Modificada | Alta (7.5) | 0.47% | — | Gpac | 9/6/2026 | 23/7/2026 | A segmentation violaton in the gf_hevc_read_sps_bs_internal function (media_tools/av_parsers.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying crafted HEVC SPS data. | |
| Modificada | Alta (7.5) | 0.50% | — | Gpac | 9/6/2026 | 23/7/2026 | A stack buffer overflow in the filein_process function (in_file.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file. | |
| Aplazada | Media (5) | 0.11% | — | Gpac Project Mp4boxAI | 3/6/2026 | 22/7/2026 | A NULL pointer dereference in the gf_filter_pid_resolve_file_template_ex function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted file. | |
| Aplazada | Media (5.5) | 0.13% | — | Gpac Project Mp4boxAI | 1/6/2026 | 22/7/2026 | A segmentation violation in the gf_media_get_color_info function (/media_tools/isom_tools.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted data file. | |
| Aplazada | Media (5.5) | 0.13% | — | Gpac Project Mp4boxAI | 1/6/2026 | 22/7/2026 | A heap use-after-free in the dasher_process function (/filters/dasher.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MPEG-2 file. | |
| Aplazada | Media (5.5) | 0.14% | — | Gpac Project Mp4boxAI | 1/6/2026 | 22/7/2026 | A segmentation violation in the gf_isom_apple_set_tag_ex function (/isomedia/isom_write.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file. | |
| Aplazada | Media (5.5) | 0.14% | — | Gpac Project Mp4boxAI | 1/6/2026 | 22/7/2026 | A NULL pointer dereference in the gf_ac4_pres_b_4_back_channels_present function (/media_tools/av_parsers.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AC4 file. | |
| Aplazada | Media (5.5) | 0.14% | — | Gpac Project Mp4boxAI | 1/6/2026 | 22/7/2026 | A NULL pointer dereference in the gf_odf_ac4_cfg_dsi_v1 function (/odf/descriptors.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AC4 file. | |
| Aplazada | Media (5.5) | 0.16% | — | Gpac Mp4boxAI | 1/6/2026 | 22/7/2026 | A heap buffer overflow in the m2tsdmx_send_packet function (filters/dmx_m2ts.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file. | |
| Aplazada | Media (4.3) | 0.44% | — | Gpac Mp4boxAI | 27/5/2026 | 5/10/2026 | A NULL pointer dereference in GPAC MP4Box: when parsing certain truncated MP4 files, an unknown/invalid stsd entry can result in missing descriptor fields (e.g., codec/mime/profile strings). gf_media_map_esd then calls strlen() on a NULL pointer, triggering a crash (ASan SEGV). | |
| Analizada | Baja (1.9) | 0.19% | — | Gpac | 26/5/2026 | 23/7/2026 | A security vulnerability has been detected in GPAC up to 2.4.0. Affected by this issue is the function Media_GetSample of the file src/isomedia/media.c of the component MP4Box. Such manipulation of the argument cat leads to memory leak. The attack can only be performed from a local environment. The exploit has been… | |
| Aplazada | Baja (1.9) | 0.16% | — | GpacAI | 26/5/2026 | 23/7/2026 | A security flaw has been discovered in GPAC up to 2.4.0. Affected is the function MergeFragment of the file src/isomedia/isom_intern.c of the component MP4Box. The manipulation results in null pointer dereference. The attack needs to be approached locally. The exploit has been released to the public and may be used… | |
| Analizada | Baja (1.9) | 0.19% | — | Gpac | 8/5/2026 | 17/6/2026 | A security vulnerability has been detected in GPAC up to 26.02.0. This affects the function sidx_box_read of the file src/isomedia/box_code_base.c. The manipulation leads to allocation of resources. The attack must be carried out locally. The exploit has been disclosed publicly and may be used. The identifier of the… | |
| Analizada | Media (5.5) | 0.16% | — | Gpac | 5/5/2026 | 17/6/2026 | Buffer Overflow vulnerability in GPAC before commit v391dc7f4d234988ea0bc3cc294eb725eddf8f702 allows an attacker to cause a denial of service via the src/scenegraph/svg_attributes.c, svg_parse_strings(), gf_svg_parse_attribute() | |
| Aplazada | Baja (1.9) | 0.16% | — | GpacAI | 27/4/2026 | 17/6/2026 | A security flaw has been discovered in GPAC up to 26.03-DEV-rev105-g8f39a1eb3-master. Affected by this vulnerability is the function elng_box_read of the file src/isomedia/box_code_base.c of the component MP4Box. Performing a manipulation of the argument elng results in out-of-bounds read. The attack needs to be… | |
| Analizada | Alta (7.5) | 0.69% | — | Shamaton Msgpack | 26/3/2026 | 17/6/2026 | The msgpack decoder fails to properly validate the input buffer length when processing truncated fixext data (format codes 0xd4-0xd8). This can lead to an out-of-bounds read and a runtime panic, allowing a denial of service attack. | |
| Analizada | Alta (7.8) | 0.17% | — | Gpac | 20/3/2026 | 17/6/2026 | GPAC is an open-source multimedia framework. Prior to commit 86b0e36, a heap-based buffer overflow (write) vulnerability was discovered in GPAC MP4Box. The vulnerability exists in the gf_xml_parse_bit_sequence_bs function in utils/xml_bin_custom.c when processing a crafted NHML file containing malicious <BS>… | |
| Aplazada | Baja (2.1) | 0.43% | — | GpacAI | 16/3/2026 | 17/6/2026 | A vulnerability was found in GPAC up to 2.5-DEV-rev2167-gcc9d617c0-master. This vulnerability affects the function swf_def_bits_jpeg of the file src/scene_manager/swf_parse.c of the component MP4Box. The manipulation of the argument szName results in stack-based buffer overflow. It is possible to launch the attack… |