Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 546 respecto a la semana anterior
Críticas / altas1325▼ 174 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 241 respecto a la semana anterior
483 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.8) | 0.30% | — | Gpac | 17/6/2024 | 17/6/2026 | A vulnerability was found in GPAC 2.5-DEV-rev228-g11067ea92-master. It has been declared as problematic. This vulnerability affects the function xmt_node_end of the file src/scene_manager/loader_xmt.c of the component MP4Box. The manipulation leads to use after free. Local access is required to approach this attack.… | |
| Modificada | Media (4.8) | 0.33% | — | Gpac | 17/6/2024 | 17/6/2026 | A vulnerability was found in GPAC 2.5-DEV-rev228-g11067ea92-master. It has been classified as problematic. This affects the function m2tsdmx_on_event of the file src/filters/dmx_m2ts.c of the component MP4Box. The manipulation leads to null pointer dereference. An attack has to be approached locally. The exploit has… | |
| Modificada | Media (4.8) | 0.35% | — | Gpac | 17/6/2024 | 17/6/2026 | A vulnerability was found in GPAC 2.5-DEV-rev228-g11067ea92-master and classified as problematic. Affected by this issue is the function swf_svg_add_iso_sample of the file src/filters/load_text.c of the component MP4Box. The manipulation leads to null pointer dereference. The attack needs to be approached locally. The… | |
| Modificada | Media (4.8) | 0.35% | — | Gpac | 17/6/2024 | 17/6/2026 | A vulnerability has been found in GPAC 2.5-DEV-rev228-g11067ea92-master and classified as problematic. Affected by this vulnerability is the function isoffin_process of the file src/filters/isoffin_read.c of the component MP4Box. The manipulation leads to infinite loop. It is possible to launch the attack on the local… | |
| Analizada | Media (6.2) | 0.24% | — | Gpac | 15/3/2024 | 17/6/2026 | gpac 2.3-DEV-rev921-g422b78ecf-master was discovered to contain an out of boundary read vulnerability via gf_dash_setup_period media_tools/dash_client.c:6374 | |
| Analizada | Alta (7.1) | 0.53% | — | Gpac | 15/3/2024 | 17/6/2026 | gpac 2.3-DEV-rev921-g422b78ecf-master was discovered to contain a out of boundary write vulnerability via swf_get_string at scene_manager/swf_parse.c:325 | |
| Analizada | Crítica (9.8) | 1.1% | — | Gpac | 9/3/2024 | 17/6/2026 | An issue was discovered in gpac version 2.3-DEV-rev588-g7edc40fee-master, allows remote attackers to execute arbitrary code, cause a denial of service (DoS), and obtain sensitive information via null pointer deference in gf_dash_setup_period component in media_tools/dash_client.c. | |
| Analizada | Alta (8.8) | 0.90% | — | Gpac | 9/3/2024 | 17/6/2026 | Heap-based Buffer Overflow vulnerability in gpac version 2.3-DEV-rev588-g7edc40fee-master, allows remote attackers to execute arbitrary code and cause a denial of service (DoS) via gf_fwrite component in at utils/os_file.c. | |
| Analizada | Alta (7.5) | 1.6% | — | Gpac | 5/2/2024 | 17/6/2026 | gpac v2.2.1 (fixed in v2.4.0) was discovered to contain a memory leak via the gfio_blob variable in the gf_fileio_from_blob function. | |
| Modificada | Alta (7.5) | 1.3% | — | Gpac | 5/2/2024 | 17/6/2026 | gpac v2.2.1 was discovered to contain a Use-After-Free (UAF) vulnerability via the dasher_configure_pid function at /src/filters/dasher.c. | |
| Modificada | Alta (7.5) | 1.3% | — | Gpac | 5/2/2024 | 17/6/2026 | gpac v2.2.1 was discovered to contain a memory leak via the dst_props variable in the gf_filter_pid_merge_properties_internal function. | |
| Modificada | Alta (7.8) | 0.53% | — | Gpac | 25/1/2024 | 17/6/2026 | GPAC v2.3 was detected to contain a buffer overflow via the function gf_isom_new_generic_sample_description function in the isomedia/isom_write.c:4577 | |
| Modificada | Media (5.5) | 0.25% | — | Gpac | 10/1/2024 | 17/6/2026 | MP4Box GPAC version 2.3-DEV-rev636-gfbd7e13aa-master was discovered to contain an infinite loop in the function av1_uvlc at media_tools/av_parsers.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted MP4 file. | |
| Modificada | Crítica (9.1) | 0.95% | — | Gpac | 8/1/2024 | 17/6/2026 | Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.3-DEV. | |
| Modificada | Crítica (9.8) | 1.0% | — | Gpac | 8/1/2024 | 17/6/2026 | Stack-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.3-DEV. | |
| Modificada | Alta (7.5) | 0.76% | — | Gpac | 3/1/2024 | 17/6/2026 | An issue discovered in GPAC 2.3-DEV-rev605-gfc9e29089-master in MP4Box in gf_avc_change_vui /afltest/gpac/src/media_tools/av_parsers.c:6872:55 allows attackers to crash the application. | |
| Modificada | Media (6.5) | 0.69% | — | Kriszyp Msgpackr | 28/12/2023 | 17/6/2026 | msgpackr is a fast MessagePack NodeJS/JavaScript implementation. Prior to 1.10.1, when decoding user supplied MessagePack messages, users can trigger stuck threads by crafting messages that keep the decoder stuck in a loop. The fix is available in v1.10.1. Exploits seem to require structured cloning, replacing the… | |
| Modificada | Crítica (9.8) | 1.1% | — | Gpac | 9/12/2023 | 17/6/2026 | Heap Buffer Overflow vulnerability in GPAC version 2.3-DEV-rev617-g671976fcc-master, allows attackers to execute arbitrary code and cause a denial of service (DoS) via str2ulong class in src/media_tools/avilib.c in gpac/MP4Box. | |
| Modificada | Media (5.5) | 0.21% | — | Gpac | 9/12/2023 | 17/6/2026 | An issue in GPAC v.2.2.1 and before allows a local attacker to cause a denial of service (DoS) via the ctts_box_read function of file src/isomedia/box_code_base.c. | |
| Modificada | Media (5.5) | 0.35% | — | Gpac | 7/12/2023 | 17/6/2026 | gpac 2.3-DEV-rev617-g671976fcc-master contains memory leaks in gf_mpd_resolve_url media_tools/mpd.c:4589. | |
| Modificada | Media (5.3) | 0.68% | — | Gpac | 7/12/2023 | 17/6/2026 | GPAC version 2.3-DEV-rev602-ged8424300-master in MP4Box contains a memory leak in NewSFDouble scenegraph/vrml_tools.c:300. This vulnerability may lead to a denial of service. | |
| Modificada | Alta (7.1) | 0.32% | — | Gpac | 20/11/2023 | 17/6/2026 | GPAC 2.3-DEV-rev617-g671976fcc-master is vulnerable to memory leaks in extract_attributes media_tools/m3u8.c:329. | |
| Modificada | Media (5.5) | 0.30% | — | Gpac | 20/11/2023 | 17/6/2026 | GPAC 2.3-DEV-rev617-g671976fcc-master is vulnerable to memory leak in gf_mpd_parse_string media_tools/mpd.c:75. | |
| Modificada | Alta (7.8) | 0.36% | — | Gpac | 15/11/2023 | 17/6/2026 | GPAC v2.3-DEV-rev566-g50c2ab06f-master was discovered to contain a stack overflow via the hevc_parse_vps_extension function at /media_tools/av_parsers.c. | |
| Modificada | Alta (7.8) | 0.34% | — | Gpac | 15/11/2023 | 17/6/2026 | GPAC v2.3-DEV-rev566-g50c2ab06f-master was discovered to contain a double free via the gf_filterpacket_del function at /gpac/src/filter_core/filter.c. |