CVE-2025-60483
A NULL pointer dereference in the gf_ac4_pres_b_4_back_channels_present function (/media_tools/av_parsers.c) of GPAC Project/MP4Box before 2
CVSS
5.5
Medium
EPSS
0.1%
p4
KEV
—
Exploit Today
1
0-100
Published: Jun 1, 2026 · Last modified: Jul 22, 2026 · CWE-476
0.1%EPSS · 30 days0.1%
2026-08-062026-09-02
A NULL pointer dereference in the gf_ac4_pres_b_4_back_channels_present function (/media_tools/av_parsers.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AC4 file.
- github.comhttps://github.com/gpac/gpac/commit/13eb5b76560aaf7813b865a2ad433258478e2695
- github.comhttps://github.com/gpac/gpac/issues/3302
- github.comhttps://github.com/sigdevel/pocs/blob/main/res/gpac/MP4Box/49/README.md
- infosec.exchangehttps://infosec.exchange/@sigdevel/116659111520602254
- www.openwall.comhttp://www.openwall.com/lists/oss-security/2026/06/01/9
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-782227.5 HIG—
——0A vulnerability exists in NGINX JavaScript where a malformed HTTP response received by ngx.fetch() can crash an NGINX worker when trusted JavaScript reads Response.statusText. Exploitation requires control or influence over the fetched HTTP response.
Impact:
This vulnerability may allow remote attackers to cause a denial-of-service (DoS) on the NGINX system. There is no control plane exposure; this is a data plane issue only.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.1dCVE-2026-829265.5 MED1.2%
——0NULL pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation.
This issue affects mTower: before afef59aa6f55c5d5ebf9b14bc020bf1c2c37489a.2dCVE-2026-828035.3 MED33.7%
——10A vulnerability has been found in armink struct2json 1.0. This affects the function S2J_STRUCT_GET_string_ELEMENT in the library struct2json/inc/s2jdef.h of the component JSON Deserialization. The manipulation of the argument valuestring leads to null pointer dereference. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.2dCVE-2026-825884.3 MED23.3%
——7A vulnerability was identified in Open5GS up to 2.7.7. This issue affects some unknown processing of the file src/amf/namf-handler.c of the component Transfer Endpoint. Such manipulation leads to null pointer dereference. The attack can be launched remotely. Upgrading to version 2.8.0 is capable of addressing this issue. The name of the patch is abf8a836564b966b5141110fc25ed413c4f17522. Upgrading the affected component is advised.2dCVE-2026-814907.7 HIG14.2%
——4A database user able to create a view in a namespace that MongoDB Connector for BI samples can cause the schema-sampling routine to stop functioning by defining a view whose evaluation reliably fails. The sampling logic classifies the resulting server message as transient and, after the configured retries are exhausted, proceeds without a valid result, ending the schema refresh routine. The mongosqld process continues running without a usable schema, so SQL clients are unable to obtain results until an operator removes the view or excludes its namespace from sampling.2dCVE-2026-76650—7.5%
——2A NULL
pointer dereference vulnerability exists in TL-WR841N v14 in the UPnP service when processing
SOAP state variable query requests. A specially crafted SOAP query may trigger
unexpected termination or instability of the process hosting the UPnP service.
Successful
exploitation may result in a denial-of-service condition affecting UPnP
discovery, state query, or related management functionality until the affected
process is restarted or the device is rebooted.2d