boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2025-60468MEDIUM
n/a n/a — GPAC Multimedia Open Source Project GPAC Project/MP4Box 2.5-DEV-rev1593-gfe88c3545-master is affected by: Buffer Overflow.
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   L   L   N  U  N  N  H    5.5   .0020   10.6     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Sep 26  Reserved by mitre
  Jun 24  EXPLOIT PUBLISHED — CVE-2025-60468. Public exploit reference added.
  Jun 24  Published (CNA: mitre)
CWE-122 · CNA: mitre · CVSS v3.1 · 5 references · NVD status: Analyzed

Description

GPAC Multimedia Open Source Project GPAC Project/MP4Box 2.5-DEV-rev1593-gfe88c3545-master is affected by: Buffer Overflow. The impact is: cause a denial of service (local). The component is: filter_core/filter_pid.c (L:574-580): function gf_filter_pid_inst_swap_delete_task() improperly accesses freed objects during PID instance swap/delete cleanup, leading to heap use-after-free. The attack vector is: Local (AV:L): a local, authenticated user who processes a specially crafted MPEG-2 TS/MP4 file with MP4Box can trigger the bug during filter teardown (PID instance swap/delete), causing a crash. ¶¶ In GPAC s MP4Box, gf_filter_pid_inst_swap_delete_task() in filter_core/filter_pid.c may dereference objects after they have been freed when cleaning up PID instances after a swap/delete operation. Crafted inputs (e.g., malformed MPEG-2 TS) can trigger a heap use-after-free and crash; exploitation may be possible.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
September 26, 2025ReservedReserved by mitre
June 24, 2026EXPLOIT PUBLISHEDEXPLOIT PUBLISHED — CVE-2025-60468. Public exploit reference added.
June 24, 2026PublishedPublished (CNA: mitre)

Affected

Affected products and packages — 1 row
VendorProduct / PackageEcosystemVersion introducedFixed
n/an/an/a

Weaknesses

CWE-122

References (5)

Related

Authoritative record: CVE-2025-60468 at cve.org

Weaknesses: CWE-122

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2025-60468 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.