CVE detail
CVE-2025-15667
A vulnerability was determined in GPAC up to 2.5-DEV. This vulnerability affects the function gf_isom_nalu_sample_rewrite of the file src/isomedia/avc_ext.c of the component MP4Box. This manipulation of the argument nalu_out_bs causes double free. It is possible to launch the attack on the local host. The exploit has been publicly disclosed and may be utilized. Patch name: f29f955f2a3b5e8e507caad3e52319f961bf37bf. To fix this issue, it is recommended to deploy a patch.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 22.0 · diversity 6.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 8
- within the 30d window
- Peak daily
- 8
- highest bucket
Evidence
Source links by recency
8 source links · newest first
- https://vuldb.com/vuln/376292/ctivuldb.com
No excerpt available.
Exploitvuldb.comJul 6, 2026, 12:16 PM - https://vuldb.com/vuln/376292vuldb.com
No excerpt available.
Exploitvuldb.comJul 6, 2026, 12:16 PM - https://vuldb.com/submit/846839vuldb.com
No excerpt available.
Exploitvuldb.comJul 6, 2026, 12:16 PM - https://vuldb.com/cve/CVE-2025-15667vuldb.com
No excerpt available.
Exploitvuldb.comJul 6, 2026, 12:16 PM - https://github.com/gpac/gpac/issues/3403github.com
No excerpt available.
Exploitgithub.comJul 6, 2026, 12:16 PM No excerpt available.
Exploitgithub.comJul 6, 2026, 12:16 PM- https://github.com/gpac/gpac/github.com
No excerpt available.
Exploitgithub.comJul 6, 2026, 12:16 PM No excerpt available.
Exploitgithub.comJul 6, 2026, 12:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-14604CVSS 2.1 · Low
A vulnerability was determined in Open Asset Import Library Assimp up to 6.0.4. Affected is the function Assimp::Exporter::ExportToBlob of the file code/AssetLib/Ply/PlyLoader.cpp…
- CVE-2026-5186CVSS 1.9 · Low
A weakness has been identified in Nothings stb up to 2.30. This impacts the function stbi__load_gif_main of the file stb_image.h of the component Multi-frame GIF File Handler. Thi…
- CVE-2025-13566CVSS 4.8 · Medium
A security vulnerability has been detected in jarun nnn up to 5.1. The impacted element is the function show_content_in_floating_window/run_cmd_as_plugin of the file nnn/src/nnn.c…
- CVE-2025-8585CVSS 1.9 · Low
A vulnerability, which was classified as critical, has been found in libav up to 12.3. Affected by this issue is the function main of the file /avtools/avconv.c of the component D…
- CVE-2025-2925CVSS 1.9 · Low
A vulnerability has been found in HDF5 up to 1.14.6 and classified as problematic. This vulnerability affects the function H5MM_realloc of the file src/H5MM.c. The manipulation of…
- CVE-2024-35814CVSS 8.8 · High
In the Linux kernel, the following vulnerability has been resolved: swiotlb: Fix double-allocation of slots due to broken alignment handling Commit bbb73a103fbb ("swiotlb: fix a…