CVE-2018-13026: Gopro Gpmf-Parser

Critical severity, CVSS 9.8. EPSS: 1.6% chance of exploitation in the next 30 days.

An issue was discovered in gpmf-parser 1.1.2. There is a heap-based buffer over-read in GPMF_parser.c in the function GPMF_Type.

Affected products

  • Gopro Gpmf-Parser: version 1.1.2 only

Published 2018-06-30. Last modified 2026-06-17.