
CVE-2024-0322 – Out-of-bounds Read in gpac/gpac
https://notcve.org/view.php?id=CVE-2024-0322
08 Jan 2024 — Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.3-DEV. Fuera de los límites Read en el repositorio de GitHub gpac/gpac anterior a 2.3-DEV. • https://github.com/gpac/gpac/commit/092904b80edbc4dce315684a59cc3184c45c1b70 • CWE-125: Out-of-bounds Read •

CVE-2023-1655 – Heap-based Buffer Overflow in gpac/gpac
https://notcve.org/view.php?id=CVE-2023-1655
27 Mar 2023 — Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.4.0. • https://github.com/gpac/gpac/commit/e7f96c2d3774e4ea25f952bcdf55af1dd6e919f4 • CWE-122: Heap-based Buffer Overflow •

CVE-2022-29340 – Gentoo Linux Security Advisory 202408-21
https://notcve.org/view.php?id=CVE-2022-29340
05 May 2022 — GPAC 2.1-DEV-rev87-g053aae8-master. has a Null Pointer Dereference vulnerability in gf_isom_parse_movie_boxes_internal due to improper return value handling of GF_SKIP_BOX, which causes a Denial of Service. This vulnerability was fixed in commit 37592ad. GPAC versión 2.1-DEV-rev87-g053aae8-master. presenta una vulnerabilidad de Desreferencia de Puntero Null en gf_isom_parse_movie_boxes_internal debido a un manejo inapropiado del valor de retorno de GF_SKIP_BOX, que causa una Denegación de Servicio. Esta vul... • https://github.com/gpac/gpac/commit/37592ad86c6ca934d34740012213e467acc4a3b0 • CWE-476: NULL Pointer Dereference •

CVE-2022-29339 – Gentoo Linux Security Advisory 202408-21
https://notcve.org/view.php?id=CVE-2022-29339
05 May 2022 — In GPAC 2.1-DEV-rev87-g053aae8-master, function BS_ReadByte() in utils/bitstream.c has a failed assertion, which causes a Denial of Service. This vulnerability was fixed in commit 9ea93a2. En GPAC versión 2.1-DEV-rev87-g053aae8-master, la función BS_ReadByte() en el archivo utils/bitstream.c presenta una aserción fallida, que causa una Denegación de Servicio. Esta vulnerabilidad fue corregida en el commit 9ea93a2 Multiple vulnerabilities have been discovered in GPAC, the worst of which could lead to arbitra... • https://github.com/gpac/gpac/commit/9ea93a2ec8f555ceed1ee27294cf94822f14f10f • CWE-617: Reachable Assertion •