Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.5 CVE-2025-55661

CVE-2025-55661_CVE-2025-55661

A heap buffer overflow in the Opus audio stream parser component of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supply...

n/a n/a n/a CVE
MEDIUM 5.5 CVE-2025-55660

CVE-2025-55660_CVE-2025-55660

A stack overflow in the gf_opus_read_length function (media_tools/av_parsers.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (...

n/a n/a n/a CVE
MEDIUM 5.5 CVE-2025-55652

CVE-2025-55652_CVE-2025-55652

A heap buffer overflow in the gf_isom_vp_config_new function (isomedia/avc_ext.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service...

n/a n/a n/a CVE
MEDIUM 5.5 CVE-2025-55650

CVE-2025-55650_CVE-2025-55650

A heap use-after-free in the gf_node_get_tag function (scenegraph/base_scenegraph.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Serv...

n/a n/a n/a CVE
MEDIUM 5.5 CVE-2025-55649

CVE-2025-55649_CVE-2025-55649

A NULL pointer dereference in the gf_media_map_esd function (media_tools/isom_tools.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Se...

n/a n/a n/a CVE
MEDIUM 5.5 CVE-2025-55648

CVE-2025-55648_CVE-2025-55648

A heap buffer overflow in the gf_opus_parse_packet_header function (media_tools/av_parsers.c) of GPAC MP4Box v2.4 allows attackers to cause a Denia...

n/a n/a n/a CVE
MEDIUM 5.5 CVE-2025-55647

CVE-2025-55647_CVE-2025-55647

An Out-of-Memory in the mp4_mux_cenc_insert_pssh function (filters/mux_isom.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (D...

n/a n/a n/a CVE
MEDIUM 5.5 CVE-2025-55645

CVE-2025-55645_CVE-2025-55645

A heap buffer overflow in the gf_cenc_set_pssh function (isomedia/drm_sample.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (...

n/a n/a n/a CVE
MEDIUM 5.5 CVE-2025-55644

CVE-2025-55644_CVE-2025-55644

A heap use-after-free in the gf_node_get_tag function (scenegraph/base_scenegraph.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Serv...

n/a n/a n/a CVE
MEDIUM 5.5 CVE-2025-55643

CVE-2025-55643_CVE-2025-55643

A NULL pointer dereference in the TrackWriter handling component (filters/mux_isom.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Ser...

n/a n/a n/a CVE