Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 6 respecto a la semana anterior
Críticas / altas1451▲ 315 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
483 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.52% | — | GpacAI | 30/9/2026 | 2/10/2026 | A weakness has been identified in GPAC up to 26.07.0. Affected by this issue is the function gf_dash_resolve_url of the file src/media_tools/dash_client.c of the component DASH Client. This manipulation causes buffer overflow. The attack is possible to be carried out remotely. Upgrading to version abi-16.26 can… | |
| Aplazada | Media (5.5) | 0.17% | — | GpacAI | 22/9/2026 | 24/9/2026 | A NULL pointer dereference vulnerability exists in the gf_sg_vrml_field_clone() function of GPAC 2d7da22e (26.08-DEV). The vulnerability occurs when cloning a PROTO default SFImage field with a NULL source pointer. An attacker can provide a specially crafted input file that triggers the condition, resulting in… | |
| Aplazada | Media (6.9) | 0.54% | — | GpacAI | 18/9/2026 | 18/9/2026 | A vulnerability was identified in GPAC 26.08-DEV. This vulnerability affects the function gf_rtp_parse_ttxt of the file src/ietf/rtp_depacketizer.c of the component RTP Depacketizer. Such manipulation of the argument size leads to out-of-bounds read. It is possible to launch the attack remotely. Upgrading to version… | |
| Aplazada | Baja (1.9) | 0.17% | — | GpacAI | 16/9/2026 | 17/9/2026 | A security flaw has been discovered in GPAC 26.08-DEV. This affects the function gf_inline_get_proto_lib of the file src/compositor/mpeg4_inline.c of the component Proto Link Handler. The manipulation results in use after free. The attack requires a local approach. The exploit has been released to the public and may… | |
| Aplazada | Baja (1.9) | 0.17% | — | GpacAI | 16/9/2026 | 17/9/2026 | A vulnerability was determined in GPAC 26.08-DEV. The affected element is the function gf_node_deactivate_ex of the file src/scenegraph/base_scenegraph.c of the component MP4Box. Executing a manipulation can lead to use after free. The attack needs to be launched locally. The exploit has been publicly disclosed and… | |
| Aplazada | Baja (1.9) | 0.16% | — | GpacAI | 16/9/2026 | 22/9/2026 | A weakness has been identified in GPAC 26.08-DEV. This impacts the function wait_for_header_and_parse of the file src/utils/downloader.c. This manipulation of the argument Content-Range causes out-of-bounds read. The attack requires local access. The exploit has been made available to the public and could be used for… | |
| Aplazada | Baja (1.9) | 0.17% | — | GpacAI | 16/9/2026 | 18/9/2026 | A vulnerability was identified in GPAC 26.08-DEV. The impacted element is the function gf_sg_command_del of the file src/scenegraph/commands.c of the component BIFS Handler. The manipulation leads to use after free. The attack needs to be performed locally. The exploit is publicly available and might be used.… | |
| Aplazada | Media (5.5) | 0.69% | — | GpacAI | 16/9/2026 | 18/9/2026 | A vulnerability was determined in GPAC 26.07.0. This affects the function rmt_client_handle_ws_frame of the file src/utils/rmt_ws.c of the component WebSocket Handler. Executing a manipulation of the argument payload_size can lead to heap-based buffer overflow. It is possible to launch the attack remotely. The exploit… | |
| Aplazada | Baja (2.1) | 0.69% | — | GpacAI | 15/9/2026 | 15/9/2026 | A vulnerability was identified in GPAC up to f1219cde. The impacted element is the function gf_node_list_insert_child of the file scenegraph/base_scenegraph.c of the component Node Insertion. Such manipulation leads to memory corruption. The attack can be launched remotely. The exploit is publicly available and might… | |
| Aplazada | Baja (0.9) | 0.17% | — | GpacAI | 15/9/2026 | 17/9/2026 | A vulnerability was determined in GPAC up to f1219cde. The affected element is the function gf_node_activate_ex of the file scenegraph/base_scenegraph.c. This manipulation causes stack-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been publicly disclosed and may be… | |
| Aplazada | Baja (2.1) | 0.51% | — | GpacAI | 15/9/2026 | 15/9/2026 | A vulnerability was found in GPAC up to f1219cde. Impacted is the function gf_node_get_name_and_id of the file scenegraph/base_scenegraph.c. The manipulation results in use after free. It is possible to launch the attack remotely. The exploit has been made public and could be used. Upgrading to version abi-16.23 is… | |
| Aplazada | Baja (2.4) | 0.16% | — | GpacAI | 15/9/2026 | 15/9/2026 | A vulnerability has been found in GPAC up to f1219cde. This issue affects the function gf_url_concatenate_ex of the file utils/url.c of the component URL Handler. The manipulation leads to heap-based buffer overflow. An attack has to be approached locally. Upgrading to version abi-16.23 is capable of addressing this… | |
| Aplazada | Media (5.5) | 0.64% | — | GpacAI | 15/9/2026 | 15/9/2026 | A flaw has been found in GPAC up to f1219cde. This vulnerability affects the function gf_mo_get_od_id of the file compositor/media_object.c of the component Compositor. Executing a manipulation can lead to use after free. The attack may be performed from remote. The exploit has been published and may be used.… | |
| Aplazada | Baja (2.1) | 0.55% | — | GpacAI | 15/9/2026 | 15/9/2026 | A security vulnerability has been detected in GPAC up to f1219cde. Affected by this issue is the function mpgviddmx_process of the file filters/reframe_mpgvid.c of the component MPEG Video Reframer. Such manipulation leads to heap-based buffer overflow. The attack can be executed remotely. The exploit has been… | |
| Aplazada | Baja (1.9) | 0.17% | — | GpacAI | 14/9/2026 | 15/9/2026 | A vulnerability was identified in GPAC 26.07.0. This affects the function gf_node_deactivate_ex of the file scenegraph/base_scenegraph.c of the component MP4Box. Such manipulation leads to use after free. The attack must be carried out locally. The exploit is publicly available and might be used. Upgrading to version… | |
| Aplazada | Baja (0.9) | 0.16% | — | GpacAI | 14/9/2026 | 16/9/2026 | A vulnerability was determined in GPAC 26.07.0. Affected by this issue is the function gf_node_del of the file scenegraph/base_scenegraph.c of the component MP4Box. This manipulation causes out-of-bounds read. The attack is restricted to local execution. The exploit has been publicly disclosed and may be utilized.… | |
| Aplazada | Baja (1.9) | 0.17% | — | GpacAIGpac Mp4boxAI | 14/9/2026 | 15/9/2026 | A vulnerability was found in GPAC 26.07.0. Affected by this vulnerability is the function gf_node_unregister of the file scenegraph/base_scenegraph.c of the component MP4Box. The manipulation results in use after free. The attack is only possible with local access. The exploit has been made public and could be used.… | |
| Aplazada | Baja (1.9) | 0.18% | — | GpacAI | 14/9/2026 | 15/9/2026 | A vulnerability has been found in GPAC 26.07.0. Affected is the function gf_sg_dom_event_bubble of the file src/scenegraph/dom_events.c of the component MP4Box. The manipulation leads to stack-based buffer overflow. The attack can only be performed from a local environment. The exploit has been disclosed to the public… | |
| Aplazada | Baja (2.1) | 0.51% | — | GpacAI | 14/9/2026 | 14/9/2026 | A vulnerability was found in GPAC up to f1219cde. The affected element is the function gf_sg_script_load of the file scenegraph/vrml_tools.c of the component MP4Box. Performing a manipulation results in use after free. It is possible to initiate the attack remotely. The exploit has been made public and could be used.… | |
| Aplazada | Baja (2.1) | 0.58% | — | GpacAI | 14/9/2026 | 16/9/2026 | A vulnerability has been found in GPAC up to f1219cde. Impacted is the function gf_node_get_name of the file scenegraph/base_scenegraph.c of the component MP4Box. Such manipulation leads to use after free. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. Upgrading… | |
| Aplazada | Baja (2.1) | 0.69% | — | GpacAI | 14/9/2026 | 14/9/2026 | A flaw has been found in GPAC up to f1219cde. This issue affects the function gf_node_list_get_child of the file scenegraph/base_scenegraph.c of the component MP4Box. This manipulation of the argument Target causes null pointer dereference. The attack is possible to be carried out remotely. The exploit has been… | |
| Aplazada | Baja (2.1) | 0.51% | — | GpacAI | 14/9/2026 | 15/9/2026 | A vulnerability was detected in GPAC up to f1219cde. This vulnerability affects the function gf_node_unregister of the file scenegraph/base_scenegraph.c of the component MP4Box. The manipulation results in use after free. The attack can be executed remotely. The exploit is now public and may be used. Upgrading to… | |
| Aplazada | Baja (2.1) | 0.51% | — | GpacAI | 14/9/2026 | 15/9/2026 | A vulnerability was determined in GPAC up to f1219cde. This vulnerability affects the function gf_node_changed_internal of the file scenegraph/base_scenegraph.c of the component MP4Box. This manipulation causes use after free. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and… | |
| Aplazada | Media (5.5) | 0.86% | — | GpacAI | 14/9/2026 | 14/9/2026 | A vulnerability was found in GPAC up to f1219cde. This affects the function gf_bt_report of the file scene_manager/loader_bt.c of the component MP4Box. The manipulation results in memory corruption. The attack may be performed from remote. The exploit has been made public and could be used. Upgrading to version… | |
| Aplazada | Baja (0.9) | 0.16% | — | GpacAIGpac Mp4boxAI | 14/9/2026 | 16/9/2026 | A vulnerability has been found in GPAC up to f1219cde. Affected by this issue is the function lsr_exec_command_list of the file laser/lsr_dec.c of the component MP4Box. The manipulation leads to reachable assertion. Local access is required to approach this attack. The exploit has been disclosed to the public and may… |