CVE-2022-36190
https://notcve.org/view.php?id=CVE-2022-36190
GPAC mp4box 2.1-DEV-revUNKNOWN-master has a use-after-free vulnerability in function gf_isom_dovi_config_get. This vulnerability was fixed in commit fef6242. GPAC mp4box versión 2.1-DEV-revUNKNOWN-master presenta una vulnerabilidad de uso de memoria previamente liberada en la función gf_isom_dovi_config_get. Esta vulnerabilidad fue corregida en el commit fef6242. • https://github.com/gpac/gpac/issues/2220 https://www.debian.org/security/2023/dsa-5411 • CWE-416: Use After Free •
CVE-2022-2549 – NULL Pointer Dereference in gpac/gpac
https://notcve.org/view.php?id=CVE-2022-2549
NULL Pointer Dereference in GitHub repository gpac/gpac prior to v2.1.0-DEV. Una Desreferencia de Puntero NULL en el repositorio de GitHub gpac/gpac versiones anteriores a 2.1.0-DEV • https://github.com/gpac/gpac/commit/0102c5d4db7fdbf08b5b591b2a6264de33867a07 https://huntr.dev/bounties/c93083dc-177c-4ba0-ba83-9d7fb29a5537 • CWE-476: NULL Pointer Dereference •
CVE-2022-2453 – Use After Free in gpac/gpac
https://notcve.org/view.php?id=CVE-2022-2453
Use After Free in GitHub repository gpac/gpac prior to 2.1-DEV. Un Uso de Memoria Previamente Liberada en el repositorio de GitHub gpac/gpac versiones anteriores a 2.1-DEV. • https://github.com/gpac/gpac/commit/dc7de8d3d604426c7a6e628d90cb9fb88e7b4c2c https://huntr.dev/bounties/c8c964de-046a-41b2-9ff5-e25cfdb36b5a • CWE-416: Use After Free •
CVE-2022-2454 – Integer Overflow or Wraparound in gpac/gpac
https://notcve.org/view.php?id=CVE-2022-2454
Integer Overflow or Wraparound in GitHub repository gpac/gpac prior to 2.1-DEV. Un Desbordamiento de Enteros o Wraparound en el repositorio de GitHub gpac/gpac versiones anteriores a 2.1-DEV. • https://github.com/gpac/gpac/commit/faa75edde3dfeba1e2cf6ffa48e45a50f1042096 https://huntr.dev/bounties/105d40d0-46d7-461e-9f8e-20c4cdea925f https://www.debian.org/security/2023/dsa-5411 • CWE-190: Integer Overflow or Wraparound •
CVE-2021-40607
https://notcve.org/view.php?id=CVE-2021-40607
The schm_box_size function in GPAC 1.0.1 allows attackers to cause a denial of service via a crafted file in the MP4Box command. La función schm_box_size de GPAC versión 1.0.1, permite a atacantes causar una denegación de servicio por medio de un archivo diseñado en el comando MP4Box • https://github.com/gpac/gpac/issues/1879 • CWE-770: Allocation of Resources Without Limits or Throttling •