Stack buffer overflow in the hevcparsevps_extension function in MP4Box in GPAC 1.0.1 allows attackers to cause a denial of service or execute arbitrary code via a crafted file.
[
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"156453034275860195751118554467831625006",
"278350946933998893876045049577207316467",
"292344529475341452140739090620657628091"
]
},
"id": "CVE-2021-33362-a4d76a98",
"signature_type": "Line",
"source": "https://github.com/gpac/gpac/commit/1273cdc706eeedf8346d4b9faa5b33435056061d",
"deprecated": false,
"target": {
"file": "src/media_tools/av_parsers.c"
},
"signature_version": "v1"
},
{
"digest": {
"function_hash": "199429521635279753719972385502701430293",
"length": 9286.0
},
"id": "CVE-2021-33362-b4046db8",
"signature_type": "Function",
"source": "https://github.com/gpac/gpac/commit/1273cdc706eeedf8346d4b9faa5b33435056061d",
"deprecated": false,
"target": {
"function": "hevc_parse_vps_extension",
"file": "src/media_tools/av_parsers.c"
},
"signature_version": "v1"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-33362.json"
"2026-04-11T17:25:57Z"