Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Gopro

First CVE: Oct 7, 2014Active for: 12 yearsTotal CVEs: 20
44.1
VTI Score
High

GoPro's vulnerability footprint centers on action camera hardware and firmware alongside its video-processing libraries, a narrowly scoped but prominently tracked product family that has accumulated significant vulnerability volume. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes, clustering in the GPMF parser and GoPro Hero firmware around memory-safety and code-injection weakness classes including out-of-bounds reads and writes, divide-by-zero conditions, and OS command injection. The parser's role in processing telemetry data from widely distributed camera hardware, combined with the firmware's embedded nature and long device lifecycles, creates a durable exposure surface where memory corruption and injection flaws pose elevated risks. Defenders should prioritize firmware updates for deployed GoPro devices and scrutinize any processing pipeline that ingests GPMF telemetry data; live severity and exploitation details are shown alongside this summary.

FAUCET AI Generated
20
Total CVEs
More Total CVEs than 96% of tracked vendors
1.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 79% of tracked vendors
8.4
Avg CVSS Score
Higher Avg CVSS Score than 82% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Gopro over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 7, 2014
11 years ago
Most Recent CVE
Oct 19, 2020
2,104 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (20 CVEs).

20 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-13009CRITICAL
An issue was discovered in gpmf-parser 1.1.2. There is a heap-based buffer over-read in GPMF_parser.c in the function GPMF_Next, related to certain checks for GPMF_KEY_END and nest
Jun 29, 20189.831NONO
CVE-2018-13008CRITICAL
An issue was discovered in gpmf-parser 1.1.2. There is a heap-based buffer over-read in GPMF_parser.c in the function GPMF_Next, related to certain checks for a positive nest_level
Jun 29, 20189.831NONO
CVE-2018-13007CRITICAL
An issue was discovered in gpmf-parser 1.1.2. There is a heap-based buffer over-read in GPMF_parser.c in the function GPMF_Next, related to certain checks for GPMF_KEY_END and nest
Jun 29, 20189.831NONO
CVE-2014-6433HIGH
gpExec in GoPro HERO 3+ allows remote attackers to execute arbitrary files via a the (1) a1 or (2) a2 parameter in a start action.
Oct 7, 201410.031NONO
CVE-2018-13011CRITICAL
An issue was discovered in gpmf-parser 1.1.2. There is a heap-based buffer over-read in GPMF_parser.c in the function GPMF_Validate.
Jun 29, 20189.830NONO
CVE-2014-6434HIGH
gpExec in GoPro HERO 3+ allows remote attackers to execute arbitrary commands via a the (1) a1 or (2) a2 parameter in a restart action.
Oct 7, 201410.030NONO
CVE-2020-16159CRITICAL
GoPro gpmf-parser 1.5 has a heap out-of-bounds read and segfault in GPMF_ScaledData(). Parsing malicious input can result in a crash or information disclosure.
Oct 19, 20209.128NONO
CVE-2018-18699HIGH
An issue was discovered in GoPro gpmf-parser 1.2.1. There is an out-of-bounds write in OpenMP4Source in GPMF_mp4reader.c.
Oct 29, 20188.827NONO
CVE-2019-20087HIGH
GoPro GPMF-parser 1.2.3 has a heap-based buffer over-read in GPMF_seekToSamples in GPMF-parse.c for the "matching tags" feature.
Dec 30, 20198.826NONO
CVE-2019-20086HIGH
GoPro GPMF-parser 1.2.3 has a heap-based buffer over-read in GPMF_Next in GPMF_parser.c.
Dec 30, 20198.826NONO
View all 20 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products20 CVEs
20%
50%
30%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local3 (15.0%)
Network15 (75.0%)
Unknown2 (10.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low18 (90.0%)
High0 (0.0%)
Unknown2 (10.0%)
User Interaction
None8 (40.0%)
Unknown2 (10.0%)
Required10 (50.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None18 (90.0%)
Unknown2 (10.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (20 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Gopro.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Gopro — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Gopro's Products

View all 1 CNAs →

Top CWEs