CVE-2023-5595 – Denial of Service in gpac/gpac
https://notcve.org/view.php?id=CVE-2023-5595
Denial of Service in GitHub repository gpac/gpac prior to 2.3.0-DEV. Denegación de Servicio en el repositorio de GitHub gpac/gpac anterior a la versión 2.3.0-DEV. • https://github.com/gpac/gpac/commit/7a6f636db3360bb16d18078d51e8c596f31302a1 https://huntr.dev/bounties/0064cf76-ece1-495d-82b4-e4a1bebeb28e • CWE-400: Uncontrolled Resource Consumption •
CVE-2023-5586 – NULL Pointer Dereference in gpac/gpac
https://notcve.org/view.php?id=CVE-2023-5586
NULL Pointer Dereference in GitHub repository gpac/gpac prior to 2.3.0-DEV. Eliminación de referencia del puntero NULL en el repositorio de GitHub gpac/gpac anterior a 2.3.0-DEV. • https://github.com/gpac/gpac/commit/ca1b48f0abe71bf81a58995d7d75dc27f5a17ddc https://huntr.dev/bounties/d2a6ea71-3555-47a6-9b18-35455d103740 • CWE-476: NULL Pointer Dereference •
CVE-2023-39562
https://notcve.org/view.php?id=CVE-2023-39562
GPAC v2.3-DEV-rev449-g5948e4f70-master was discovered to contain a heap-use-after-free via the gf_bs_align function at bitstream.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via supplying a crafted file. • https://github.com/ChanStormstout/Pocs/blob/master/gpac_POC/id%3A000000%2Csig%3A06%2Csrc%3A003771%2Ctime%3A328254%2Cexecs%3A120473%2Cop%3Ahavoc%2Crep%3A8 https://github.com/gpac/gpac/issues/2537 • CWE-416: Use After Free •
CVE-2023-37174
https://notcve.org/view.php?id=CVE-2023-37174
GPAC v2.3-DEV-rev381-g817a848f6-master was discovered to contain a segmentation violation in the dump_isom_scene function at /mp4box/filedump.c. • https://github.com/gpac/gpac/issues/2505 • CWE-787: Out-of-bounds Write •
CVE-2023-37765
https://notcve.org/view.php?id=CVE-2023-37765
GPAC v2.3-DEV-rev381-g817a848f6-master was discovered to contain a segmentation violation in the gf_dump_vrml_sffield function at /lib/libgpac.so. • https://github.com/gpac/gpac/issues/2515 • CWE-787: Out-of-bounds Write •