Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2624▼ 223 respecto a la semana anterior
Críticas / altas1373▲ 144 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
16 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (1.9) | 0.17% | — | GpacAIGpac Mp4boxAI | 14/9/2026 | 15/9/2026 | A vulnerability was found in GPAC 26.07.0. Affected by this vulnerability is the function gf_node_unregister of the file scenegraph/base_scenegraph.c of the component MP4Box. The manipulation results in use after free. The attack is only possible with local access. The exploit has been made public and could be used.… | |
| Aplazada | Baja (0.9) | 0.16% | — | GpacAIGpac Mp4boxAI | 14/9/2026 | 16/9/2026 | A vulnerability has been found in GPAC up to f1219cde. Affected by this issue is the function lsr_exec_command_list of the file laser/lsr_dec.c of the component MP4Box. The manipulation leads to reachable assertion. Local access is required to approach this attack. The exploit has been disclosed to the public and may… | |
| Aplazada | Baja (1.9) | 0.17% | — | GpacAIGpac Mp4boxAI | 14/9/2026 | 15/9/2026 | A vulnerability was determined in GPAC up to f1219cde. This impacts the function xmt_parse_element of the file scene_manager/loader_xmt.c of the component MP4Box. Executing a manipulation can lead to reachable assertion. The attack is restricted to local execution. The exploit has been publicly disclosed and may be… | |
| Aplazada | Media (5) | 0.11% | — | Gpac Project Mp4boxAI | 3/6/2026 | 22/7/2026 | A NULL pointer dereference in the gf_filter_pid_resolve_file_template_ex function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted file. | |
| Aplazada | Media (5.5) | 0.13% | — | Gpac Project Mp4boxAI | 1/6/2026 | 22/7/2026 | A segmentation violation in the gf_media_get_color_info function (/media_tools/isom_tools.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted data file. | |
| Aplazada | Media (5.5) | 0.13% | — | Gpac Project Mp4boxAI | 1/6/2026 | 22/7/2026 | A heap use-after-free in the dasher_process function (/filters/dasher.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MPEG-2 file. | |
| Aplazada | Media (5.5) | 0.14% | — | Gpac Project Mp4boxAI | 1/6/2026 | 22/7/2026 | A segmentation violation in the gf_isom_apple_set_tag_ex function (/isomedia/isom_write.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file. | |
| Aplazada | Media (5.5) | 0.14% | — | Gpac Project Mp4boxAI | 1/6/2026 | 22/7/2026 | A NULL pointer dereference in the gf_ac4_pres_b_4_back_channels_present function (/media_tools/av_parsers.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AC4 file. | |
| Aplazada | Media (5.5) | 0.14% | — | Gpac Project Mp4boxAI | 1/6/2026 | 22/7/2026 | A NULL pointer dereference in the gf_odf_ac4_cfg_dsi_v1 function (/odf/descriptors.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AC4 file. | |
| Aplazada | Media (5.5) | 0.16% | — | Gpac Mp4boxAI | 1/6/2026 | 22/7/2026 | A heap buffer overflow in the m2tsdmx_send_packet function (filters/dmx_m2ts.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file. | |
| Aplazada | Media (4.3) | 0.41% | — | Gpac Mp4boxAI | 27/5/2026 | 17/6/2026 | A NULL pointer dereference in GPAC MP4Box: when parsing certain truncated MP4 files, an unknown/invalid stsd entry can result in missing descriptor fields (e.g., codec/mime/profile strings). gf_media_map_esd then calls strlen() on a NULL pointer, triggering a crash (ASan SEGV). | |
| Aplazada | Alta (7.8) | 0.25% | — | Gpac Mp4boxAI | 24/1/2025 | 17/6/2026 | GPAC MP4box 2.1-DEV-rev574-g9d5bb184b contains a buffer overflow in gf_vvc_read_pps_bs_internal function of media_tools/av_parsers.c, check needed for num_exp_tile_columns | |
| Modificada | Media (5.5) | 0.60% | — | Gpac Mp4box | 16/6/2022 | 17/6/2026 | In GPAC MP4Box v1.1.0, there is a stack buffer overflow at src/utils/error.c:1769 which leads to a denial of service vulnerability. | |
| Modificada | Alta (7.5) | 1.3% | — | Gpac Mp4box | 1/10/2021 | 17/6/2026 | There is a stack buffer overflow in MP4Box v1.0.1 at src/filters/dmx_nhml.c:1008 in the nhmldmx_send_sample() function szXmlFrom parameter which leads to a denial of service vulnerability. | |
| Modificada | Alta (7.5) | 1.2% | — | Gpac Mp4box | 1/10/2021 | 17/6/2026 | There is a stack buffer overflow in MP4Box 1.1.0 at src/filters/dmx_nhml.c in nhmldmx_init_parsing which leads to a denial of service vulnerability. | |
| Modificada | Alta (7.5) | 1.2% | — | Gpac Mp4box | 1/10/2021 | 17/6/2026 | There is a stack buffer overflow in MP4Box v1.0.1 at src/filters/dmx_nhml.c:1004 in the nhmldmx_send_sample() function szXmlTo parameter which leads to a denial of service vulnerability. |