GoPro's vulnerability footprint centers on action camera hardware and firmware alongside its video-processing libraries, a narrowly scoped but prominently tracked product family that has accumulated significant vulnerability volume. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes, clustering in the GPMF parser and GoPro Hero firmware around memory-safety and code-injection weakness classes including out-of-bounds reads and writes, divide-by-zero conditions, and OS command injection. The parser's role in processing telemetry data from widely distributed camera hardware, combined with the firmware's embedded nature and long device lifecycles, creates a durable exposure surface where memory corruption and injection flaws pose elevated risks. Defenders should prioritize firmware updates for deployed GoPro devices and scrutinize any processing pipeline that ingests GPMF telemetry data; live severity and exploitation details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gopro over time
Signals from CVEs in this vendor scope (20 CVEs).
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-13009CRITICAL An issue was discovered in gpmf-parser 1.1.2. There is a heap-based buffer over-read in GPMF_parser.c in the function GPMF_Next, related to certain checks for GPMF_KEY_END and nest | Jun 29, 2018 | 9.8 | 31 | NO | NO |
CVE-2018-13008CRITICAL An issue was discovered in gpmf-parser 1.1.2. There is a heap-based buffer over-read in GPMF_parser.c in the function GPMF_Next, related to certain checks for a positive nest_level | Jun 29, 2018 | 9.8 | 31 | NO | NO |
CVE-2018-13007CRITICAL An issue was discovered in gpmf-parser 1.1.2. There is a heap-based buffer over-read in GPMF_parser.c in the function GPMF_Next, related to certain checks for GPMF_KEY_END and nest | Jun 29, 2018 | 9.8 | 31 | NO | NO |
CVE-2014-6433HIGH gpExec in GoPro HERO 3+ allows remote attackers to execute arbitrary files via a the (1) a1 or (2) a2 parameter in a start action. | Oct 7, 2014 | 10.0 | 31 | NO | NO |
CVE-2018-13011CRITICAL An issue was discovered in gpmf-parser 1.1.2. There is a heap-based buffer over-read in GPMF_parser.c in the function GPMF_Validate. | Jun 29, 2018 | 9.8 | 30 | NO | NO |
CVE-2014-6434HIGH gpExec in GoPro HERO 3+ allows remote attackers to execute arbitrary commands via a the (1) a1 or (2) a2 parameter in a restart action. | Oct 7, 2014 | 10.0 | 30 | NO | NO |
CVE-2020-16159CRITICAL GoPro gpmf-parser 1.5 has a heap out-of-bounds read and segfault in GPMF_ScaledData(). Parsing malicious input can result in a crash or information disclosure. | Oct 19, 2020 | 9.1 | 28 | NO | NO |
CVE-2018-18699HIGH An issue was discovered in GoPro gpmf-parser 1.2.1. There is an out-of-bounds write in OpenMP4Source in GPMF_mp4reader.c. | Oct 29, 2018 | 8.8 | 27 | NO | NO |
CVE-2019-20087HIGH GoPro GPMF-parser 1.2.3 has a heap-based buffer over-read in GPMF_seekToSamples in GPMF-parse.c for the "matching tags" feature. | Dec 30, 2019 | 8.8 | 26 | NO | NO |
CVE-2019-20086HIGH GoPro GPMF-parser 1.2.3 has a heap-based buffer over-read in GPMF_Next in GPMF_parser.c. | Dec 30, 2019 | 8.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (20 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gopro.
Media articles that mention a CVE ID that affects a product developed by Gopro — matched by CVE ID, not by vendor name.