Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Gpac

First CVE: Mar 6, 2018Active for: 8 yearsTotal CVEs: 406
32.7
VTI Score
Medium

Gpac is a multimedia framework and toolkit with a surprisingly large vulnerability footprint concentrated in a narrowly scoped product portfolio, centered on the widely used MP4Box utility. The exposure recurs consistently through memory-safety weaknesses including NULL-pointer dereferences, out-of-bounds reads and writes, and integer-overflow conditions that cascade into buffer overflows, typical of C-based media parsing and encoding libraries that process untrusted input. These classes of flaw arise from the complexity of multimedia container formats and the low-level buffer manipulation required to parse and transcode media files, making them a durable structural signature of this vendor's codebase. Defenders should treat Gpac as a supply-chain component and monitor downstream products and workflows that integrate this toolkit or invoke MP4Box, since vulnerability patches may require coordinated updates across dependent applications. Current severity, exploitation status, and exposure counts are shown alongside this summary.

FAUCET AI Generated
406
Total CVEs
More Total CVEs than 100% of tracked vendors
22.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 100% of tracked vendors
6.5
Avg CVSS Score
Higher Avg CVSS Score than 41% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Gpac over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 6, 2018
8 years ago
Most Recent CVE
Jun 25, 2026
29 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (406 CVEs).

406 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-60467HIGH
A use-after-free in the gf_filter_pid_inst_swap_delete_task function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service
Jun 24, 20267.535NONO
CVE-2025-60474HIGH
A buffer overflow in the gf_media_import function (/media_tools/av_parsers.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplyin
Jun 24, 20267.535NONO
CVE-2025-60464HIGH
A use-after-free in the gf_sei_load_from_state_internal function (/filters/sei_load.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via
Jun 25, 20267.833NONO
CVE-2018-13006CRITICAL
An issue was discovered in MP4Box in GPAC 0.7.1. There is a heap-based buffer over-read in the isomedia/box_dump.c function hdlr_dump.
Jun 29, 20189.832NONO
CVE-2018-13005CRITICAL
An issue was discovered in MP4Box in GPAC 0.7.1. The function urn_Read in isomedia/box_code_base.c has a heap-based buffer over-read.
Jun 29, 20189.832NONO
CVE-2025-52292HIGH
A stack buffer overflow in the filein_process function (in_file.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.
Jun 9, 20267.530NONO
CVE-2025-52293HIGH
A segmentation violaton in the gf_hevc_read_sps_bs_internal function (media_tools/av_parsers.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplyin
Jun 9, 20267.530NONO
CVE-2025-55657HIGH
A NULL pointer dereference in the gf_odf_vvc_cfg_write_bs function (odf/descriptors.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a craft
Jun 9, 20267.530NONO
CVE-2026-33144HIGH
GPAC is an open-source multimedia framework. Prior to commit 86b0e36, a heap-based buffer overflow (write) vulnerability was discovered in GPAC MP4Box. The vulnerability exists in
Mar 20, 20267.830NONO
CVE-2025-70298HIGH
GPAC v2.4.0 was discovered to contain an out-of-bounds read in the oggdmx_parse_tags function.
Jan 15, 20268.230NONO
View all 406 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products406 CVEs
59%
37%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local324 (79.8%)
Network82 (20.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low406 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None60 (14.8%)
Unknown0 (0.0%)
Required346 (85.2%)
Privileges Required
Low17 (4.2%)
High0 (0.0%)
None389 (95.8%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (406 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Gpac.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Gpac — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Gpac's Products

View all 6 CNAs →

Top CWEs