
CVE-2023-46931
https://notcve.org/view.php?id=CVE-2023-46931
01 Nov 2023 — GPAC 2.3-DEV-rev605-gfc9e29089-master contains a heap-buffer-overflow in ffdmx_parse_side_data /afltest/gpac/src/filters/ff_dmx.c:202:14 in gpac/MP4Box. GPAC 2.3-DEV-rev605-gfc9e29089-master contiene un desbordamiento de búfer de montón en ffdmx_parse_side_data /afltest/gpac/src/filters/ff_dmx.c:202:14 en gpac/MP4Box. • https://github.com/gpac/gpac/commit/671976fccc971b3dff8d3dcf6ebd600472ca64bf. • CWE-787: Out-of-bounds Write •

CVE-2023-46928
https://notcve.org/view.php?id=CVE-2023-46928
01 Nov 2023 — GPAC 2.3-DEV-rev605-gfc9e29089-master contains a SEGV in gpac/MP4Box in gf_media_change_pl /afltest/gpac/src/media_tools/isom_tools.c:3293:42. GPAC 2.3-DEV-rev605-gfc9e29089-master contiene un SEGV en gpac/MP4Box en gf_media_change_pl /afltest/gpac/src/media_tools/isom_tools.c:3293:42. • https://github.com/gpac/gpac/commit/0753bf6d867343a80a044bf47a27d0b7accc8bf1 • CWE-787: Out-of-bounds Write •

CVE-2023-46930
https://notcve.org/view.php?id=CVE-2023-46930
01 Nov 2023 — GPAC 2.3-DEV-rev605-gfc9e29089-master contains a SEGV in gpac/MP4Box in gf_isom_find_od_id_for_track /afltest/gpac/src/isomedia/media_odf.c:522:14. GPAC 2.3-DEV-rev605-gfc9e29089-master contiene un SEGV en gpac/MP4Box en gf_isom_find_od_id_for_track /afltest/gpac/src/isomedia/media_odf.c:522:14. • https://github.com/gpac/gpac/commit/3809955065afa3da1ad580012ec43deadbb0f2c8 • CWE-787: Out-of-bounds Write •

CVE-2023-46927
https://notcve.org/view.php?id=CVE-2023-46927
01 Nov 2023 — GPAC 2.3-DEV-rev605-gfc9e29089-master contains a heap-buffer-overflow in gf_isom_use_compact_size gpac/src/isomedia/isom_write.c:3403:3 in gpac/MP4Box. GPAC 2.3-DEV-rev605-gfc9e29089-master contiene un desbordamiento de búfer de montón en gf_isom_use_compact_size gpac/src/isomedia/isom_write.c:3403:3 en gpac/MP4Box. • https://github.com/gpac/gpac/commit/a7b467b151d9b54badbc4dd71e7a366b7c391817 • CWE-787: Out-of-bounds Write •

CVE-2023-5595 – Denial of Service in gpac/gpac
https://notcve.org/view.php?id=CVE-2023-5595
16 Oct 2023 — Denial of Service in GitHub repository gpac/gpac prior to 2.3.0-DEV. Denegación de Servicio en el repositorio de GitHub gpac/gpac anterior a la versión 2.3.0-DEV. • https://github.com/gpac/gpac/commit/7a6f636db3360bb16d18078d51e8c596f31302a1 • CWE-400: Uncontrolled Resource Consumption •

CVE-2023-5586 – NULL Pointer Dereference in gpac/gpac
https://notcve.org/view.php?id=CVE-2023-5586
15 Oct 2023 — NULL Pointer Dereference in GitHub repository gpac/gpac prior to 2.3.0-DEV. Eliminación de referencia del puntero NULL en el repositorio de GitHub gpac/gpac anterior a 2.3.0-DEV. • https://github.com/gpac/gpac/commit/ca1b48f0abe71bf81a58995d7d75dc27f5a17ddc • CWE-476: NULL Pointer Dereference •

CVE-2023-42298
https://notcve.org/view.php?id=CVE-2023-42298
12 Oct 2023 — An issue in GPAC GPAC v.2.2.1 and before allows a local attacker to cause a denial of service via the Q_DecCoordOnUnitSphere function of file src/bifs/unquantize.c. Un problema en GPAC GPAC v.2.2.1 y anteriores permite que un atacante local provoque una Denegación de Servicio (DoS) a través de la función Q_DecCoordOnUnitSphere del archivo src/bifs/unquantize.c. • https://github.com/gpac/gpac/issues/2567 • CWE-190: Integer Overflow or Wraparound •

CVE-2023-5520 – Out-of-bounds Read in gpac/gpac
https://notcve.org/view.php?id=CVE-2023-5520
11 Oct 2023 — Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.2.2. Fuera de los Límites Leído en el repositorio de GitHub gpac/gpac anterior a 2.2.2. It was discovered that the GPAC MP4Box utility incorrectly handled certain AC3 files, which could lead to an out-of-bounds read. A remote attacker could use this issue to cause MP4Box to crash, resulting in a denial of service. This issue only affected Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. • https://github.com/gpac/gpac/commit/5692dc729491805e0e5f55c21d50ba1e6b19e88e • CWE-125: Out-of-bounds Read •

CVE-2023-5377 – Out-of-bounds Read in gpac/gpac
https://notcve.org/view.php?id=CVE-2023-5377
04 Oct 2023 — Out-of-bounds Read in GitHub repository gpac/gpac prior to v2.2.2-DEV. Lectura fuera de límites en el repositorio de GitHub gpac/gpac anterior a v2.2.2-DEV. • https://github.com/gpac/gpac/commit/8e9d6b38c036a97020c462ad48e1132e0ddc57ce • CWE-125: Out-of-bounds Read •

CVE-2023-41000
https://notcve.org/view.php?id=CVE-2023-41000
11 Sep 2023 — GPAC through 2.2.1 has a use-after-free vulnerability in the function gf_bifs_flush_command_list in bifs/memory_decoder.c. GPAC hasta la versión 2.2.1 tiene una vulnerabilidad de use-after-free en la función gf_bifs_flush_command_list en bifs/memory_decoder.c. • https://github.com/gpac/gpac/issues/2550 • CWE-416: Use After Free •