CVE Feed

    Dashboard / CVE / CVE-2021-40574

    CVE-2021-40574

    The binary MP4Box in Gpac from 0.9.0-preview to 1.0.1 has a double-free vulnerability in the gf_text_get_utf8_line function in load_text.c, which allows attackers to cause a denial of service, even code execution and escalation of privileges.

    Published:Jan 13, 2022
    Last Modified:Mar 5, 2025
    EPS:Jan 13, 2022
    EPSS Score:0.00409
    CVSS Score:7.8

    Affected Products

    Vendor
    Gpac
    Product
    Gpac

    Common Weakness Enumeration

    Common Attack Pattern Enumeration and Classification (CAPEC)

    No CAPEC recorded yet

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High