CVE-2025-60485
A segmentation violation in the gf_isom_apple_set_tag_ex function (/isomedia/isom_write.c) of GPAC Project/MP4Box before 26.02.0 allows atta
CVSS
5.5
Medio
EPSS
0.1%
p4
KEV
—
Exploit Today
1
0-100
Publicado: 1 jun 2026 · Última mod.: 22 jul 2026 · CWE-476
0.1%EPSS · 30 días0.1%
2026-06-302026-07-26
A segmentation violation in the gf_isom_apple_set_tag_ex function (/isomedia/isom_write.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.
- github.comhttps://github.com/gpac/gpac/commit/4860a1a6f128ccc9ae37b4b738d22029f9672457
- github.comhttps://github.com/gpac/gpac/issues/3323
- github.comhttps://github.com/sigdevel/pocs/blob/main/res/gpac/MP4Box/52/README.md
- infosec.exchangehttps://infosec.exchange/@sigdevel/116662498332150083
- www.openwall.comhttp://www.openwall.com/lists/oss-security/2026/06/01/11
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-17574——
———HDF5 contains a NULL pointer dereference vulnerability. Processing a crafted HDF5 file containing an attribute with an invalid variable-length datatype type field may cause the application to crash when the attribute is read.11hCVE-2026-175005.3 MED—
——0A vulnerability was detected in ggml-org llama.cpp d006858/e15efe0. This affects the function _visit_pattern of the file common/json-schema-to-grammar.cpp. The manipulation results in null pointer dereference. The attack can be launched remotely. The pull request to fix this issue awaits acceptance.10hCVE-2026-458167.5 ALT30.6%
——9NULL Pointer Dereference vulnerability in Apache NimBLE in LE Long Term Key Request event.
This requires disabled asserts (otherwise assert would trigger before NULL dereference) and bogus (or misbehaving) controller, thus severity is low.
This issue affects Apache NimBLE: through 1.9.0.
Users are recommended to upgrade to version 1.10.0, which fixes the issue.15hCVE-2026-500327.5 ALT18.0%
——5A NULL pointer dereference in the MMS Write Named Variable List handler, which may allow a network adjacent attacker to crash the server by sending a WriteRequest with an empty listOfData field.4dCVE-2026-130705.3 MED0.5%
——0A MongoDB server initiating an outbound TLS connection may terminate abnormally when processing a malformed OCSP response from a remote peer during the TLS handshake. OCSP stapling validation is enabled by default for outgoing TLS connections. Affected scenarios require the remote peer to hold a certificate issued by the cluster's trusted certificate authority, or for the connection to traverse an untrusted network path.5dCVE-2026-130656.5 MED22.7%
——7A user with read-only privileges is able to craft an aggregation pipeline using the $linearFill window function operator with a specific sortBy expression type to cause the mongod process to terminate abnormally, resulting in denial of service. The issue stems from insufficient validation of sort specifications during execution.5d