Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3192 articles · 168085 vulns · 37/41 feeds (7d)
← Back to list
7.5
CVE-2025-60474EXPLOITED
gpac project · mp4box

CVE-2025-60474: A buffer overflow in the gf_media_import function (/media_tools/av_parsers.c) of GPAC Project/MP4Box before 26.02.0 allo

Description

A buffer overflow in the gf_media_import function (/media_tools/av_parsers.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.

Affected Products

VendorProductVersions
gpac projectmp4boxn/a

References

  • https://github.com/gpac/gpac/issues/3287
  • https://github.com/gpac/gpac/commit/bd7fd6be546e0cd9e599c6b262c338c5f2ecec5c
  • https://github.com/sigdevel/pocs/blob/main/res/gpac/MP4Box/38/38_gf_media_import_media_tools_media_import_c_1297
  • https://github.com/sigdevel/pocs/blob/main/res/gpac/MP4Box/38/README.md
  • https://infosec.exchange/@sigdevel/116780566799952592

Related News (2 articles)

Tier C
oss-security23h ago
CVE-2025-60474: Heap-based Buffer Overflow in GPAC/MP4Box via gf_media_import on crafted MPEG-2 TS file
→ No new info (linked only)
Tier C
VulDB2d ago
CVE-2025-60474 | GPAC up to 26.1.x MP4Box av_parsers.c gf_media_import buffer overflow (Issue 3287)
→ No new info (linked only)
CVSS 3.17.5 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA KEV❌ No
Actively exploited✅ Yes
PublishedJun 24, 2026
Last enriched23h agov3
Trending Score67
Source articles2
Independent2
Info Completeness9/14
Missing: epss, kev, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2025-60467EXP
CVE-2025-60467: A use-after-free in the gf_filter_pid_inst_swap_delete_task function (/filter_core/filter_pid.c) of GPAC Project/MP4Box
Trending: 60
HIGHCVE-2025-60464EXP
CVE-2025-60464: A use-after-free in the gf_sei_load_from_state_internal function (/filters/sei_load.c) of GPAC Project/MP4Box before 26.
Trending: 59
MEDIUMCVE-2025-60466EXP
CVE-2025-60466: A use-after-free in the gf_filter_pid_get_packet function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.0
Trending: 55
MEDIUMCVE-2025-60465EXP
CVE-2025-60465: A use-after-free in the gf_filter_pid_inst_swap function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02
Trending: 55
MEDIUMCVE-2025-60473EXP
CVE-2025-60473: A NULL pointer dereference in the gf_filter_in_parent_chain function (/filter_core/filter_pid.c) of GPAC Project/MP4Box
Trending: 55

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 24, 2026
Discovered by ZDM
Jun 24, 2026
Updated: description, vendor, affectedVersions, severity, exploitAvailable, activelyExploited
Jun 25, 2026
Updated: description, affectedVersions, severity, cvssEstimate, cweIds
Jun 27, 2026
Actively Exploited
Jun 27, 2026
Exploit Available
Jun 27, 2026

Version History

v3
Last enriched 23h ago
v3Tier C23h ago

Updated description with more technical detail, changed severity to MEDIUM, and updated CVSS score to 4.3 with new CWE-122.

descriptionaffectedVersionsseveritycvssEstimatecweIds
via oss-security
v2Tier C2d ago

Updated vendor to GPAC, product to MP4Box, affected versions to 26.1.x, severity to CRITICAL, and marked the vulnerability as actively exploited with an exploit available.

descriptionvendoraffectedVersionsseverityexploitAvailableactivelyExploited
via VulDB
v13d ago

Initial creation