By vendor
Gpac vulnerabilities
Known CVEs affecting Gpac products, prioritized by severity, with SEC.co remediation and detection guidance.
28 published vulnerabilities
- CVE-2025-60464HIGH 7.8
A use-after-free vulnerability exists in GPAC Project's MP4Box tool, specifically in code that processes supplemental enhancement information (SEI) data from MPEG-2 transport stream files. An attacker can craft a malicious MPEG-2 TS file that, when processed by vulnerable versions of MP4Box, triggers a memory safety error leading to denial of service. The application crashes when attempting to access memory that has already been freed, preventing legitimate media processing tasks.
- CVE-2025-52292HIGH 7.5
GPAC MP4Box version 2.4 contains a stack buffer overflow vulnerability in its file input handling code. An attacker can exploit this by submitting a specially crafted MP4 file, causing the application to crash or become unresponsive. This is a denial-of-service issue with no data theft or system compromise risk, but it can disrupt services that depend on MP4Box for media processing.
- CVE-2025-52293HIGH 7.5
CVE-2025-52293 is a crash vulnerability in GPAC MP4Box v2.4 that occurs when the HEVC video parser encounters malformed video stream headers. An attacker can craft a specially designed HEVC Sequence Parameter Set (SPS) and deliver it to a system running MP4Box to trigger a segmentation fault, causing the application to crash and become unavailable. This is a network-exploitable denial-of-service issue that requires no user interaction or special privileges to trigger.
- CVE-2025-55657HIGH 7.5
GPAC MP4Box version 2.4 contains a defect that causes the application to crash when processing a specially crafted MP4 file. An attacker can exploit this by sending a malicious MP4 to any system running the vulnerable software, resulting in service unavailability. No data theft or system compromise occurs—the impact is limited to denial of service.
- CVE-2025-60467HIGH 7.5
GPAC Project's MP4Box, a multimedia framework tool, contains a flaw where freed memory is inadvertently accessed during specific filter cleanup operations. An attacker can exploit this by providing a maliciously crafted media file, crashing the application and disrupting service availability. This vulnerability affects versions before 26.02.0.
- CVE-2025-60474HIGH 7.5
A buffer overflow vulnerability in GPAC Project's MP4Box media processing tool can crash the application when given a specially crafted input file. While attackers cannot steal data or modify files through this flaw, they can disrupt services that rely on MP4Box for media processing. The vulnerability affects versions before 26.02.0 and requires no authentication or user interaction beyond supplying the malicious file.
- CVE-2025-55639MEDIUM 6.5
GPAC's MP4Box version 2.4 contains a flaw that can crash the application when processing a specially crafted MP4 file. An attacker can exploit this by distributing a malicious MP4 that triggers a crash in any system using MP4Box to process or validate video files, disrupting availability without requiring special privileges or authentication.
- CVE-2025-55642MEDIUM 6.5
GPAC MP4Box version 2.4 contains a flaw that can cause the application to crash when processing certain MP4 files. The vulnerability exists in code responsible for handling audio and video data during file writing operations. An attacker could craft a malicious MP4 file that, when opened in MP4Box, triggers a mathematical error leading to a denial of service. No data theft or file corruption occurs, but the crash prevents legitimate work with video files.
- CVE-2025-55658MEDIUM 6.5
GPAC MP4Box version 2.4 contains a bug in how it processes Opus audio codec headers within MP4 files. When processing a specially crafted MP4 file, the application crashes due to a floating point exception—essentially a mathematical error in code that causes the program to terminate. An attacker can exploit this by distributing a malicious MP4 file, causing MP4Box to crash whenever a user or automated system tries to process it. This is a denial-of-service vulnerability that affects availability but does not compromise data confidentiality or integrity.
- CVE-2025-55659MEDIUM 6.5
GPAC MP4Box version 2.4 contains a flaw that causes the application to crash when processing a specially crafted MP4 media file. An attacker can exploit this by distributing a malicious MP4 file that, when opened by a user, triggers a denial of service condition. The vulnerability does not compromise data confidentiality or integrity—it simply stops the application from functioning until it is restarted.
- CVE-2025-60465MEDIUM 6.1
A use-after-free memory vulnerability exists in GPAC's media file processing logic. When MP4Box or the GPAC library processes a specially crafted media file, it can access memory that has already been freed, triggering a crash. An attacker needs only to trick a user into opening a malicious file locally—no network interaction required. The impact is denial of service; while the vulnerability does involve memory corruption, the specific attack vector does not lead to code execution in the current configuration.
- CVE-2025-55641MEDIUM 5.5
GPAC MP4Box version 2.4 contains a flaw that can crash when processing a specially crafted MP4 video file. A user who opens a malicious MP4 file in MP4Box will experience a denial-of-service condition, rendering the tool unavailable. This is a local vulnerability requiring user interaction—the attacker must trick someone into opening a malicious file.
- CVE-2025-55643MEDIUM 5.5
CVE-2025-55643 is a denial-of-service vulnerability in GPAC MP4Box v2.4 that occurs when the application processes a specially crafted MP4 file. The flaw stems from a NULL pointer dereference in the TrackWriter handling code, which causes the application to crash. An attacker can exploit this by distributing a malicious MP4 file that, when opened by a user, terminates the MP4Box process. This is a local attack requiring user interaction—the victim must open the file—but no special privileges are needed.
- CVE-2025-55644MEDIUM 5.5
A memory safety flaw in GPAC MP4Box version 2.4 allows an attacker to crash the application by submitting a specially crafted MP4 video file. The vulnerability stems from improper handling of memory references in the scene graph processing code, where the application attempts to access memory that has already been freed. An attacker would need local access or the ability to trick a user into opening a malicious MP4 file.
- CVE-2025-55645MEDIUM 5.5
CVE-2025-55645 is a memory safety issue in GPAC MP4Box v2.4 that can be triggered by opening a specially crafted MP4 file. The vulnerability exists in code that handles digital rights management (DRM) protection information within MP4 containers. An attacker who creates a malicious MP4 file can cause the application to crash, denying service to legitimate users. The vulnerability requires local file system access and user interaction to trigger—an attacker cannot exploit it remotely over the network.
- CVE-2025-55647MEDIUM 5.5
GPAC MP4Box version 2.4 contains a flaw that causes the application to consume excessive memory and crash when processing a maliciously crafted MP4 file. An attacker can exploit this by distributing a specially designed MP4 that triggers an out-of-memory condition during the CENC (Common Encryption) PSSH (Protection System Specific Header) insertion process, effectively denying service to users attempting to process the file.
- CVE-2025-55648MEDIUM 5.5
GPAC's MP4Box version 2.4 contains a memory handling defect that can be triggered by opening a specially crafted MP4 media file. The vulnerability allows an attacker to crash the application, disrupting work for anyone using the tool to process or analyze video files. An attacker would need local access or the ability to deliver a malicious file to a target user, but no special privileges or complex exploitation steps are required once the file is opened.
- CVE-2025-55649MEDIUM 5.5
CVE-2025-55649 is a NULL pointer dereference vulnerability in GPAC MP4Box v2.4 that crashes the application when processing a maliciously crafted MP4 file. An attacker can trigger a denial-of-service condition by supplying a specially constructed media file, rendering the tool temporarily unavailable. This is a local attack that requires user interaction—the victim must open the malicious MP4 file—but does not require any elevated privileges.
- CVE-2025-55650MEDIUM 5.5
CVE-2025-55650 is a memory safety flaw in GPAC MP4Box v2.4 that occurs when the application processes a specially crafted MP4 file. The vulnerability causes the program to access memory that has already been freed (a 'use-after-free' condition), leading to a crash or denial of service. An attacker would need to trick a user into opening a malicious MP4 file, but no special privileges are required to exploit it.
- CVE-2025-55651MEDIUM 5.5
CVE-2025-55651 is a denial-of-service vulnerability in GPAC's MP4Box v2.4 that crashes the application when processing a specially crafted MP4 file. The flaw stems from the software attempting to access memory without first checking whether a critical pointer is valid. An attacker can exploit this by distributing a malformed MP4 file; if a user opens it with the vulnerable version, the application will crash. This is a local attack requiring user interaction—someone must open the malicious file—but no special privileges are needed.
- CVE-2025-55652MEDIUM 5.5
A memory corruption vulnerability exists in GPAC MP4Box version 2.4 that can be triggered by opening a specially crafted MP4 media file. The flaw is in code responsible for handling video codec configuration data, and exploiting it causes the application to crash, resulting in a denial of service. An attacker would need to trick a user into opening a malicious MP4 file locally on their system to trigger the vulnerability.
- CVE-2025-55660MEDIUM 5.5
CVE-2025-55660 is a stack overflow vulnerability in GPAC's MP4Box tool version 2.4. When a user opens a specially crafted MP4 video file, the vulnerability triggers a crash that renders the application temporarily unusable. An attacker would need to trick a user into opening a malicious MP4 file; the vulnerability does not allow remote code execution or data theft, but causes a denial of service. This is a localized threat affecting anyone using MP4Box to process untrusted video files.
- CVE-2025-55661MEDIUM 5.5
GPAC MP4Box version 2.4 contains a memory safety defect in its Opus audio parser that can be triggered by opening a specially crafted MP4 file. The flaw causes the application to crash, denying service to legitimate users. An attacker needs only local file access and user interaction (opening the file); no special privileges or network connectivity are required.
- CVE-2025-55663MEDIUM 5.5
GPAC MP4Box version 2.4 contains a crash vulnerability in how it processes MP4 video files. When a specially crafted MP4 file is opened, the application can crash due to improper memory handling in the track descriptor function. This is a local issue—an attacker would need to trick a user into opening a malicious file—but the impact is straightforward: service disruption. Media processing pipelines, automated transcoding systems, and any workflow relying on MP4Box could experience unexpected downtime.
- CVE-2025-60468MEDIUM 5.5
GPAC's MP4Box multimedia processing tool contains a memory safety defect that allows local users to crash the application by processing specially crafted video files. When MP4Box handles certain malformed MPEG-2 Transport Stream or MP4 files during filter cleanup operations, it attempts to access memory that has already been freed, triggering a denial-of-service condition. The flaw requires local system access and authenticated user privileges to exploit.
- CVE-2025-60471MEDIUM 5.5
GPAC Project's MP4Box, a widely-used multimedia processing tool, contains a use-after-free memory flaw in its filter configuration logic. When processing a specially crafted media file, the vulnerable code attempts to access memory that has already been freed, causing the application to crash. An attacker can exploit this by distributing a malicious media file that, when opened by a user, brings down MP4Box. This is a denial-of-service vulnerability—it doesn't steal data or grant unauthorized access, but it can disrupt workflows that depend on MP4Box for media processing.
- CVE-2025-60473MEDIUM 5.5
A flaw in GPAC Project's MP4Box media processing tool (versions before 26.02.0) can be triggered by opening a specially crafted media file, causing the application to crash. The vulnerability stems from improper handling of null pointers in the filter chain processing logic. While the crash itself doesn't lead to data theft or system compromise, it disrupts media processing workflows and could be weaponized in batch processing environments to degrade service availability.
- CVE-2025-60466MEDIUM 5.0
GPAC MP4Box versions before 26.02.0 contain a memory safety flaw where freed memory can be accessed during packet filtering operations. An attacker who supplies a specially crafted media file can trigger a crash or service interruption. The vulnerability requires local access and user interaction (opening the file), limiting its direct remote exploitation potential but posing a risk in automated or batch processing environments.