Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3192 articles · 168085 vulns · 37/41 feeds (7d)
← Back to list
5.5
CVE-2025-60473EXPLOITED
gpac project · mp4box

CVE-2025-60473: A NULL pointer dereference in the gf_filter_in_parent_chain function (/filter_core/filter_pid.c) of GPAC Project/MP4Box

Description

A NULL pointer dereference in the gf_filter_in_parent_chain function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted file.

Affected Products

VendorProductVersions
gpac projectmp4boxn/a

References

  • https://github.com/gpac/gpac/issues/3285
  • https://github.com/gpac/gpac/commit/b8d80b44718de10b101e1d7fc17c84d69feb092e
  • https://github.com/sigdevel/pocs/blob/main/res/gpac/MP4Box/36/README.md
  • https://infosec.exchange/@sigdevel/116780471059317580
  • https://github.com/sigdevel/pocs/blob/main/res/gpac/MP4Box/36/36_gf_filter_in_parent_chain_filter_core_filter_pid_c_2145

Related News (2 articles)

Tier C
oss-security23h ago
CVE-2025-60473: NULL Pointer Dereference in GPAC/MP4Box via gf_filter_in_parent_chain on crafted MPEG-2 TS file
→ No new info (linked only)
Tier C
VulDB2d ago
CVE-2025-60473 | GPAC up to 26.1.x MP4Box filter_pid.c gf_filter_in_parent_chain null pointer dereference (Issue 3285)
→ No new info (linked only)
CVSS 3.15.5 MEDIUM
VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CISA KEV❌ No
Actively exploited✅ Yes
PublishedJun 24, 2026
Last enriched23h agov3
Trending Score55
Source articles2
Independent2
Info Completeness9/14
Missing: epss, kev, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2025-60474EXP
CVE-2025-60474: A buffer overflow in the gf_media_import function (/media_tools/av_parsers.c) of GPAC Project/MP4Box before 26.02.0 allo
Trending: 67
HIGHCVE-2025-60467EXP
CVE-2025-60467: A use-after-free in the gf_filter_pid_inst_swap_delete_task function (/filter_core/filter_pid.c) of GPAC Project/MP4Box
Trending: 60
HIGHCVE-2025-60464EXP
CVE-2025-60464: A use-after-free in the gf_sei_load_from_state_internal function (/filters/sei_load.c) of GPAC Project/MP4Box before 26.
Trending: 59
MEDIUMCVE-2025-60466EXP
CVE-2025-60466: A use-after-free in the gf_filter_pid_get_packet function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.0
Trending: 55
MEDIUMCVE-2025-60465EXP
CVE-2025-60465: A use-after-free in the gf_filter_pid_inst_swap function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02
Trending: 55

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 24, 2026
Discovered by ZDM
Jun 25, 2026
Updated: vendor, affectedVersions, severity, exploitAvailable, activelyExploited
Jun 25, 2026
Updated: description, affectedVersions, cvssEstimate, cweIds
Jun 27, 2026
Actively Exploited
Jun 27, 2026
Exploit Available
Jun 27, 2026

Version History

v3
Last enriched 23h ago
v3Tier C23h ago

Updated description with more technical detail, affected versions, CVSS score to 4.3, and added CWE-476.

descriptionaffectedVersionscvssEstimatecweIds
via oss-security
v2Tier C2d ago

Updated vendor to GPAC Project, product to MP4Box, affected versions to 26.1.x, severity to HIGH, and marked exploit as available and actively exploited.

vendoraffectedVersionsseverityexploitAvailableactivelyExploited
via VulDB
v13d ago

Initial creation