|
101
|
7.5 |
HIGH
Network
|
gpac
|
gpac
|
A stack buffer overflow in the filein_process function (in_file.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.
New
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2025-52292
|
2026-06-13 01:52 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
102
|
6.5 |
MEDIUM
Network
|
gpac
|
gpac
|
A NULL pointer dereference in the ctts_box_write function (isomedia/box_code_base.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.
New
|
CWE-476
NULL Pointer Dereference
|
CVE-2025-55659
|
2026-06-13 01:51 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
103
|
6.5 |
MEDIUM
Network
|
gpac
|
gpac
|
GPAC MP4Box v2.4 was discovered to contain a floating point exception in the gf_opus_parse_packet_header function (media_tools/av_parsers.c). bThis vulnerability allows attackers to cause a Denial of…
New
|
CWE-1077
Floating Point Comparison with Incorrect Operator
|
CVE-2025-55658
|
2026-06-13 01:46 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
104
|
7.5 |
HIGH
Network
|
gpac
|
gpac
|
A NULL pointer dereference in the gf_odf_vvc_cfg_write_bs function (odf/descriptors.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.
New
|
CWE-476
NULL Pointer Dereference
|
CVE-2025-55657
|
2026-06-13 01:45 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
105
|
5.5 |
MEDIUM
Local
|
gpac
|
gpac
|
A NULL pointer dereference in the gf_isom_get_user_data_count function (isomedia/isom_read.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.
New
|
CWE-476
NULL Pointer Dereference
|
CVE-2025-55651
|
2026-06-13 01:39 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
106
|
7.5 |
HIGH
Network
|
gpac
|
gpac
|
A segmentation violaton in the gf_hevc_read_sps_bs_internal function (media_tools/av_parsers.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying crafted HEVC SPS …
New
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2025-52293
|
2026-06-13 01:39 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
107
|
4.4 |
MEDIUM
Network
|
-
|
-
|
IPAM is the IP address Manager for Cluster API Provider Metal3. Prior to versions 1.11.7, 1.12.4, and 1.13.0, the IPAM controller's ClusterRole granted full CRUD permissions (create, delete, get, lis…
New
|
CWE-250
Execution with Unnecessary Privileges
|
CVE-2026-47190
|
2026-06-13 01:24 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
108
|
- |
|
-
|
-
|
A lack of authorization validation in version 0.4.17 or later of the ChromaDB Python project allows any authenticated users to arbitrarily read, write, update, or delete data in any tenant's collecti…
New
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-45830
|
2026-06-13 01:23 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
109
|
- |
|
-
|
-
|
The SimpleRBACAuthorizationProvider authorization provider in versions 0.5.0 or later of the ChromaDB Python project evaluates whether a user holds a given permission but never checks which tenant, d…
New
|
CWE-863
Incorrect Authorization
|
CVE-2026-45831
|
2026-06-13 01:23 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
110
|
- |
|
-
|
-
|
All V1 collection-level endpoints in ChromaDB's Python project pass None for the tenant and database to the authorization layer, allowing attackers to bypass authorization controls by using the V1 en…
New
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-45832
|
2026-06-13 01:23 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|