CVE-2025-55642Medium· 6.5▾ SunlitGPAC MP4Box v2.4 was discovered to contain a floating point exception in the avidmx_process function (isomedia/isom_write.c).
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.5%
GPAC MP4Box v2.4 was discovered to contain a floating point exception in the avidmx_process function (isomedia/isom_write.c).
gpac < 26.02.0Upgrade past the affected range:
gpac 26.02.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-79513Medium· 6.5A divide-by-zero vulnerability in the gf_dash_get_timeline_duration function (src/media_tools/dash_client.c) of GPAC v26.07.0 allows attackers to cause a Denial of Service (DoS) via a crafted MPD SegmentTimeline
CVE-2025-55639Medium· 6.5GPAC MP4Box v2.4 was discovered to contain a NULL pointer dereference in the gf_isom_add_track_kind() function at isomedia/isom_write.c
CVE-2026-103227Medium· 6.3A weakness has been identified in GPAC up to 26.07.0
CVE-2026-93331High· 7.3A vulnerability was identified in GPAC 26.08-DEV
CVE-2026-92474Low· 3.3A security flaw has been discovered in GPAC 26.08-DEV
CVE-2026-92475Medium· 5.3A weakness has been identified in GPAC 26.08-DEV