Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
483 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (1.9) | 0.16% | — | GpacAI | 12/3/2026 | 17/6/2026 | A security vulnerability has been detected in GPAC 26.03-DEV. Affected by this vulnerability is the function svgin_process of the file src/filters/load_svg.c of the component SVG Parser. The manipulation leads to out-of-bounds write. Local access is required to approach this attack. The exploit has been disclosed… | |
| Aplazada | Baja (1.9) | 0.17% | — | GpacAI | 12/3/2026 | 17/6/2026 | A weakness has been identified in GPAC 26.03-DEV. Affected is the function txtin_process_texml of the file src/filters/load_text.c of the component TeXML File Parser. Executing a manipulation can lead to stack-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been made… | |
| Analizada | Alta (7.7) | 0.40% | — | Gpac | 26/2/2026 | 17/6/2026 | GPAC is an open-source multimedia framework. In versions up to and including 26.02.0, a stack buffer overflow occurs during NHML file parsing in `src/filters/dmx_nhml.c`. The value of the xmlHeaderEnd XML attribute is copied from att->value into szXmlHeaderEnd[1000] using strcpy() without any length validation. If the… | |
| Modificada | Baja (1.9) | 0.24% | — | Gpac | 26/1/2026 | 17/6/2026 | A security vulnerability has been detected in GPAC up to 2.4.0. This affects the function gf_text_import_srt_bifs of the file src/scene_manager/text_to_bifs.c of the component SRT Subtitle Import. Such manipulation leads to out-of-bounds write. The attack needs to be performed locally. The exploit has been disclosed… | |
| Modificada | Baja (1.9) | 0.22% | — | Gpac | 26/1/2026 | 17/6/2026 | A weakness has been identified in GPAC up to 2.4.0. Affected by this issue is the function dump_isom_rtp of the file applications/mp4box/filedump.c. This manipulation causes null pointer dereference. The attack needs to be launched locally. The exploit has been made available to the public and could be used for… | |
| Modificada | Baja (1.9) | 0.22% | — | Gpac | 26/1/2026 | 17/6/2026 | A security flaw has been discovered in GPAC up to 2.4.0. Affected by this vulnerability is the function DumpMovieInfo of the file applications/mp4box/filedump.c. The manipulation results in null pointer dereference. The attack must be initiated from a local position. The exploit has been released to the public and may… | |
| Modificada | Baja (1.9) | 0.18% | — | Gpac | 26/1/2026 | 17/6/2026 | A vulnerability was identified in GPAC up to 2.4.0. Affected is the function gf_media_export_webvtt_metadata of the file src/media_tools/media_export.c. The manipulation of the argument Name leads to null pointer dereference. The attack must be carried out locally. The exploit is publicly available and might be used.… | |
| Analizada | Media (5.5) | 0.22% | — | Gpac | 15/1/2026 | 17/6/2026 | A heap overflow in the uncv_parse_config() function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted MP4 file. | |
| Analizada | Media (5.5) | 0.22% | — | Gpac | 15/1/2026 | 17/6/2026 | A heap overflow in the ghi_dmx_declare_opid_bin() function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted input. | |
| Analizada | Alta (7.5) | 0.49% | — | Gpac | 15/1/2026 | 17/6/2026 | A stack overflow in the dump_ttxt_sample function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted packet. | |
| Analizada | Media (6.5) | 0.35% | — | Gpac | 15/1/2026 | 17/6/2026 | A heap overflow in the avi_parse_input_file() function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted AVI file. | |
| Analizada | Media (5.5) | 0.17% | — | Gpac | 15/1/2026 | 17/6/2026 | A heap overflow in the vorbis_to_intern() function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted .ogg file. | |
| Analizada | Media (5.5) | 0.17% | — | Gpac | 15/1/2026 | 17/6/2026 | A stack overflow in the pcmreframe_flush_packet function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted WAV file. | |
| Analizada | Alta (7.5) | 0.37% | — | Gpac | 15/1/2026 | 17/6/2026 | An out-of-bounds read in the GSF demuxer filter component of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted .gsf file. | |
| Analizada | Media (5.5) | 0.22% | — | Gpac | 15/1/2026 | 17/6/2026 | A stack overflow in the dmx_saf function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted .saf file. | |
| Analizada | Alta (7.5) | 0.39% | — | Gpac | 15/1/2026 | 17/6/2026 | A buffer overflow in the vobsub_get_subpic_duration() function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted packet. | |
| Analizada | Alta (8.2) | 0.43% | — | Gpac | 15/1/2026 | 17/6/2026 | GPAC v2.4.0 was discovered to contain an out-of-bounds read in the oggdmx_parse_tags function. | |
| Analizada | Alta (7.5) | 0.60% | — | Msgpack Messagepack | 2/1/2026 | 17/6/2026 | MessagePack for Java is a serializer implementation for Java. A denial-of-service vulnerability exists in versions prior to 0.9.11 when deserializing .msgpack files containing EXT32 objects with attacker-controlled payload lengths. While MessagePack-Java parses extension headers lazily, it later trusts the declared… | |
| Analizada | Media (5.5) | 0.95% | — | Gpac | 18/7/2025 | 17/6/2026 | A vulnerability was found in GPAC up to 2.4. It has been rated as problematic. Affected by this issue is the function gf_dash_download_init_segment of the file src/media_tools/dash_client.c. The manipulation of the argument base_init_url leads to null pointer dereference. The attack may be launched remotely. The… | |
| Analizada | Alta (8.4) | 0.36% | — | Gpac | 28/2/2025 | 17/6/2026 | Buffer Overflow vulnerability in GPAC version 2.5 allows a local attacker to execute arbitrary code. | |
| Analizada | Media (5.5) | 0.35% | — | Gpac | 24/1/2025 | 17/6/2026 | An issue was discovered in GPAC v0.8.0, as demonstrated by MP4Box. It contains a heap-based buffer overflow in gf_m2ts_process_pmt in media_tools/mpegts.c:2163 that can cause a denial of service (DOS) via a crafted MP4 file. | |
| Aplazada | Alta (7.8) | 0.25% | — | Gpac Mp4boxAI | 24/1/2025 | 17/6/2026 | GPAC MP4box 2.1-DEV-rev574-g9d5bb184b contains a buffer overflow in gf_vvc_read_pps_bs_internal function of media_tools/av_parsers.c, check needed for num_exp_tile_columns | |
| Analizada | Media (5.5) | 0.25% | — | Gpac | 23/1/2025 | 17/6/2026 | gpac 2.4 contains a SEGV at src/isomedia/drm_sample.c:1562:96 in isom_cenc_get_sai_by_saiz_saio in MP4Box. | |
| Analizada | Alta (7.8) | 0.28% | — | Gpac | 23/1/2025 | 17/6/2026 | gpac 2.4 contains a heap-buffer-overflow at isomedia/sample_descs.c:1799 in gf_isom_new_mpha_description in gpac/MP4Box. | |
| Analizada | Media (5.5) | 0.27% | — | Gpac | 15/11/2024 | 17/6/2026 | A use after free vulnerability exists in GPAC version 2.3-DEV-revrelease, specifically in the gf_filterpacket_del function in filter_core/filter.c at line 38. This vulnerability can lead to a double-free condition, which may cause the application to crash. |