An issue was discovered in MP4Box in GPAC 0.7.1. The function urnRead in isomedia/boxcodebase.c has a heap-based buffer over-read.
An issue was discovered in MP4Box in GPAC 0.7.1. There is a heap-based buffer over-read in the isomedia/boxdump.c function hdlrdump.
GPAC through 0.7.1 has a Buffer Overflow in the gfmediaavcreadsps function in mediatools/avparsers.c, a different vulnerability than CVE-2018-1000100.
In GPAC 0.7.1 and earlier, gftextgetutf8line in mediatools/textimport.c in libgpacstatic.a allows an out-of-bounds write because a certain -1 return value is mishandled.