VYPR

Bento4

by Bento4

Source repositories

CVEs (176)

  • CVE-2022-3665HigOct 26, 2022
    risk 0.48cvss 7.3epss 0.01

    A vulnerability classified as critical was found in Axiomatic Bento4. Affected by this vulnerability is an unknown functionality of the file AvcInfo.cpp of the component avcinfo. The manipulation leads to heap-based buffer overflow. The attack can be launched remotely. The…

  • CVE-2022-3664HigOct 26, 2022
    risk 0.48cvss 7.3epss 0.01

    A vulnerability classified as critical has been found in Axiomatic Bento4. Affected is the function AP4_BitStream::WriteBytes of the file Ap4BitStream.cpp of the component avcinfo. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack…

  • CVE-2022-3662HigOct 26, 2022
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in Axiomatic Bento4. It has been declared as critical. This vulnerability affects the function GetOffset of the file Ap4Sample.h of the component mp42hls. The manipulation leads to use after free. The attack can be initiated remotely. The exploit has…

  • CVE-2025-25944HigFeb 19, 2025
    risk 0.47cvss 7.3epss 0.00

    Buffer Overflow vulnerability in Bento4 v.1.6.0-641 allows a local attacker to execute arbitrary code via the Ap4RtpAtom.cpp, specifically in AP4_RtpAtom::AP4_RtpAtom, during the execution of mp4fragment with a crafted MP4 input file.

  • CVE-2020-19719MedJul 13, 2021
    risk 0.43cvss 6.5epss 0.06

    A buffer overflow vulnerability in Ap4ElstAtom.cpp of Bento 1.5.1-628 leads to a denial of service (DOS).

  • CVE-2025-25945MedFeb 19, 2025
    risk 0.42cvss 6.5epss 0.00

    An issue in Bento4 v1.6.0-641 allows an attacker to obtain sensitive information via the the Mp4Fragment.cpp and in AP4_DescriptorFactory::CreateDescriptorFromStream at Ap4DescriptorFactory.cpp.

  • CVE-2025-25942MedFeb 19, 2025
    risk 0.42cvss 6.5epss 0.00

    An issue in Bento4 v1.6.0-641 allows an attacker to obtain sensitive information via the the mp4fragment tool when processing invalid files. Specifically, memory allocated in SampleArray::SampleArray in Mp4Fragment.cpp is not properly released.

  • CVE-2024-57598MedFeb 5, 2025
    risk 0.42cvss 6.5epss 0.00

    A floating point exception (divide-by-zero) vulnerability was discovered in Bento4 1.6.0-641 in function AP4_TfraAtom() of Ap4TfraAtom.cpp which allows a remote attacker to cause a denial of service vulnerability.

  • CVE-2024-57513MedJan 29, 2025
    risk 0.42cvss 6.5epss 0.00

    A floating-point exception (FPE) vulnerability exists in the AP4_TfraAtom::AP4_TfraAtom function in Bento4.

  • CVE-2024-30806MedApr 2, 2024
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in Bento4 v1.6.0-641-2-g1529b83. There is a heap overflow in AP4_Dec3Atom::AP4_Dec3Atom at Ap4Dec3Atom.cpp, leading to a Denial of Service (DoS), as demonstrated by mp42aac.

  • CVE-2024-24155MedFeb 29, 2024
    risk 0.42cvss 6.5epss 0.01

    Bento4 v1.5.1-628 contains a Memory leak on AP4_Movie::AP4_Movie, parsing tracks and added into m_Tracks list, but mp42aac cannot correctly delete when we got an no audio track found error. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted mp4…

  • CVE-2024-25451MedFeb 9, 2024
    risk 0.42cvss 6.5epss 0.01

    Bento4 v1.6.0-640 was discovered to contain an out-of-memory bug via the AP4_DataBuffer::ReallocateBuffer() function.

  • CVE-2022-43038MedOct 19, 2022
    risk 0.42cvss 6.5epss 0.01

    Bento4 v1.6.0-639 was discovered to contain a heap overflow via the AP4_BitReader::ReadCache() function in mp42ts.

  • CVE-2022-43037MedOct 19, 2022
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in Bento4 1.6.0-639. There is a memory leak in the function AP4_File::ParseStream in /Core/Ap4File.cpp.

  • CVE-2022-43035MedOct 19, 2022
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in Bento4 v1.6.0-639. There is a heap-buffer-overflow in AP4_Dec3Atom::AP4_Dec3Atom at Ap4Dec3Atom.cpp, leading to a Denial of Service (DoS), as demonstrated by mp42aac.

  • CVE-2022-43034MedOct 19, 2022
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in Bento4 v1.6.0-639. There is a heap buffer overflow vulnerability in the AP4_BitReader::SkipBits(unsigned int) function in mp42ts.

  • CVE-2022-43033MedOct 19, 2022
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in Bento4 1.6.0-639. There is a bad free in the component AP4_HdlrAtom::~AP4_HdlrAtom() which allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2022-43032MedOct 19, 2022
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in Bento4 v1.6.0-639. There is a memory leak in AP4_DescriptorFactory::CreateDescriptorFromStream in Core/Ap4DescriptorFactory.cpp, as demonstrated by mp42aac.

  • CVE-2022-41427MedOct 3, 2022
    risk 0.42cvss 6.5epss 0.01

    Bento4 v1.6.0-639 was discovered to contain a memory leak in the AP4_AvcFrameParser::Feed function in mp4mux.

  • CVE-2022-41426MedOct 3, 2022
    risk 0.42cvss 6.5epss 0.01

    Bento4 v1.6.0-639 was discovered to contain a memory leak via the AP4_AtomFactory::CreateAtomFromStream function in mp4split.

Page 4 of 9