CVE-2018-18699: Gopro Gpmf-Parser

High severity, CVSS 8.8. EPSS: 1.4% chance of exploitation in the next 30 days.

An issue was discovered in GoPro gpmf-parser 1.2.1. There is an out-of-bounds write in OpenMP4Source in GPMF_mp4reader.c.

Affected products

  • Gopro Gpmf-Parser: version 1.2.1 only

Published 2018-10-29. Last modified 2026-06-17.