CVE-2021-21861
An exploitable integer truncation vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. When processing the 'hdlr' FOURCC code, a specially crafted MPEG-4 input can cause an improper memory allocation resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user to open a video to trigger this vulnerability.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.8
- CVSS vector
- CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS probability
- 0.42%
- CWE
- CWE-680
- Published
- 2021-08-16
- Last modified
- 2026-03-13
Affected products
- n/a GPAC Project
Weakness type
Related vulnerabilities
- CVE-2021-21783 — A code execution vulnerability exists in the WS-Addressing plugin functionality of Genivia gSOAP 2.8.107. A specially cr
- CVE-2021-40417 — When parsing a file that is submitted to the DPDecoder service as a job, the service will use the combination of decodin
- CVE-2020-13576 — A code execution vulnerability exists in the WS-Addressing plugin functionality of Genivia gSOAP 2.8.107. A specially cr
- CVE-2022-24834 — Heap overflow issue with the Lua cjson library used by Redis
- CVE-2025-53630 — Integer Overflow in GGUF Parser can lead to Heap Out-of-Bounds Read/Write in gguf
- CVE-2020-6099 — An exploitable code execution vulnerability exists in the file format parsing functionality of Graphisoft BIMx Desktop V
- CVE-2021-32765 — Integer Overflow to Buffer Overflow in Hiredis
- CVE-2021-21862 — Multiple exploitable integer truncation vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Proje