CVE-2020-23928: Gpac
High severity, CVSS 7.1. EPSS: 0.9% chance of exploitation in the next 30 days.
An issue was discovered in gpac before 1.0.1. The abst_box_read function in box_code_adobe.c has a heap-based buffer over-read.
Affected products
- Gpac Gpac: before 1.0.1 (fixed in 1.0.1)
Published 2021-04-21. Last modified 2026-06-17.