GPAC 在提交 f1219cde 之前的版本中存在一个缺陷。该漏洞影响 MP4Box 组件中 文件里的 函数。执行特定操作可能导致“释放后使用”(use after free)问题。该攻击局限于本地执行环境。相关利用代码(exploit)已公开,可能被利用。升级到版本 abi-16.23 可以解决此问题。该补丁的标识为 49dee5cad329cfed310c1682703df7daa47df31a。建议升级受影响的组件以修复此漏洞。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | GPAC | f1219cde |
cpe:2.3:a:gpac:gpac:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-90577 | 5.3 MEDIUM | GPAC MP4Box base_scenegraph.c gf_node_get_field heap-based overflow |
| CVE-2026-90529 | 3.5 LOW | DataEase Symbolic Map symbolic-map.ts buildTooltip cross site scripting |
| CVE-2026-90576 | 3.3 LOW | GPAC MP4Box base_scenegraph.c gf_node_list_add_child null pointer dereference |
| CVE-2026-90573 | 3.3 LOW | GPAC MP4Box vrml_tools.c gf_sg_mfurl_del null pointer dereference |
| CVE-2025-70819 | Zettlab D6 Ultra 1.7.0以下路径穿越挂载漏洞 |
No comments yet