Page 21 of 315 results (0.004 seconds)

CVSS: 7.8EPSS: 0%CPEs: 2EXPL: 1

MP4Box is a component of GPAC-2.0.0, which is a widely-used third-party package on RPM Fusion. When MP4Box tries to parse a MP4 file, it calls the function `diST_box_read()` to read from video. In this function, it allocates a buffer `str` with fixed length. However, content read from `bs` is controllable by user, so is the length, which causes a buffer overflow. MP4Box es un componente de GPAC-2.0.0, que es un paquete de terceros ampliamente usado en RPM Fusion. • https://github.com/gpac/gpac/commit/3dbe11b37d65c8472faf0654410068e5500b3adb https://github.com/gpac/gpac/issues/2175 https://www.debian.org/security/2023/dsa-5411 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer CWE-125: Out-of-bounds Read •

CVSS: 5.5EPSS: 0%CPEs: 1EXPL: 1

gp_rtp_builder_do_hevc in ietf/rtp_pck_mpeg4.c in GPAC 2.0.0 has a heap-based buffer over-read, as demonstrated by MP4Box. La función gp_rtp_builder_do_hevc en el archivo ietf/rtp_pck_mpeg4.c en GPAC 2.0.0, presenta una lectura excesiva del búfer en la región heap de la memoria, como es demostrado en MP4Box • https://github.com/gpac/gpac/issues/2173 https://www.debian.org/security/2023/dsa-5411 • CWE-125: Out-of-bounds Read •

CVSS: 5.5EPSS: 0%CPEs: 1EXPL: 1

GPAC mp4box 1.1.0-DEV-rev1663-g881c6a94a-master is vulnerable to Integer Overflow. GPAC mp4box versión 1.1.0-DEV-rev1663-g881c6a94a-master, es vulnerable a un desbordamiento de enteros • https://github.com/gpac/gpac/issues/2067 • CWE-190: Integer Overflow or Wraparound •

CVSS: 5.5EPSS: 0%CPEs: 1EXPL: 1

GPAC mp4box 1.1.0-DEV-rev1759-geb2d1e6dd-has a heap-buffer-overflow vulnerability in function gf_isom_apple_enum_tag. GPAC mp4box versión 1.1.0-DEV-rev1759-geb2d1e6dd, presenta una vulnerabilidad de desbordamiento del búfer de la pila en la función gf_isom_apple_enum_tag • https://github.com/gpac/gpac/issues/2120 • CWE-787: Out-of-bounds Write •

CVSS: 5.5EPSS: 0%CPEs: 1EXPL: 1

GPAC mp4box 1.1.0-DEV-rev1727-g8be34973d-master has a stack-overflow vulnerability in function gf_isom_get_sample_for_movie_time of mp4box. GPAC mp4box versión 1.1.0-DEV-rev1727-g8be34973d-master, presenta una vulnerabilidad de desbordamiento de pila en la función gf_isom_get_sample_for_movie_time de mp4box • https://github.com/gpac/gpac/issues/2108 https://www.debian.org/security/2023/dsa-5411 • CWE-787: Out-of-bounds Write •