在 GPAC(版本 up to f1219cde)中发现一个漏洞。受影响的是 文件中的 函数,属于 MP4Box 组件。执行特定操作会触发可达到的断言失败。该漏洞需要本地访问才能利用。该漏洞的利用方式现已公开,可能被攻击者使用。升级到版本 abi-16.23 可以解决此问题。补丁提交名为 。建议升级受影响的组件。此漏洞并非 CVE-2021-46237 或 CVE-2021-46234 的重复项。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | GPAC | f1219cde |
cpe:2.3:a:gpac:gpac:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-90687 | 6.3 MEDIUM | GPAC MP4Box base_scenegraph.c gf_node_changed_internal use after free |
| CVE-2026-90686 | 5.3 MEDIUM | GPAC MP4Box loader_bt.c gf_bt_report memory corruption |
| CVE-2026-90613 | 3.3 LOW | GPAC MP4Box stbl_read.c stbl_GetSampleInfos assertion |
| CVE-2026-90612 | 3.3 LOW | GPAC MP4Box scene_dump.c gf_sm_dump_command_list assertion |
| CVE-2026-90611 | 3.3 LOW | GPAC MP4Box loader_xmt.c xmt_parse_element assertion |
| CVE-2026-90610 | 3.3 LOW | GPAC MP4Box svg_attributes.c gf_svg_attributes_copy buffer over-read |
| CVE-2026-90609 | 3.3 LOW | GPAC MP4Box vrml_tools.c null pointer dereference |
| CVE-2026-90685 | 2.8 LOW | GPAC MP4Box lsr_dec.c lsr_exec_command_list assertion |
| CVE-2026-90684 | 2.8 LOW | GPAC MP4Box base_scenegraph.c gf_node_get_field_count assertion |
| CVE-2023-50462 | TYPO3 content_consent 2.0.1 IDOR 漏洞 |
No comments yet