VYPR

Bento4

by Bento4

Source repositories

CVEs (176)

  • CVE-2022-41425MedOct 3, 2022
    risk 0.42cvss 6.5epss 0.01

    Bento4 v1.6.0-639 was discovered to contain a segmentation violation via the AP4_Processor::ProcessFragments function in mp4decrypt.

  • CVE-2022-41424MedOct 3, 2022
    risk 0.42cvss 6.5epss 0.01

    Bento4 v1.6.0-639 was discovered to contain a memory leak via the AP4_SttsAtom::Create function in mp42hls.

  • CVE-2022-41423MedOct 3, 2022
    risk 0.42cvss 6.5epss 0.01

    Bento4 v1.6.0-639 was discovered to contain a segmentation violation in the mp4fragment component.

  • CVE-2022-41419MedOct 3, 2022
    risk 0.42cvss 6.5epss 0.01

    Bento4 v1.6.0-639 was discovered to contain a memory leak via the AP4_Processor::Process function in the mp4encrypt binary.

  • CVE-2022-40738MedSep 15, 2022
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in Bento4 through 1.6.0-639. A NULL pointer dereference occurs in AP4_DescriptorListWriter::Action in Core/Ap4Descriptor.h, called from AP4_EsDescriptor::WriteFields and AP4_Expandable::Write.

  • CVE-2022-40737MedSep 15, 2022
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in Bento4 through 1.6.0-639. A buffer over-read exists in the function AP4_StdcFileByteStream::WritePartial located in System/StdC/Ap4StdCFileByteStream.cpp, called from AP4_ByteStream::Write and AP4_HdlrAtom::WriteFields.

  • CVE-2022-40736MedSep 15, 2022
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in Bento4 1.6.0-639. There ie excessive memory consumption in AP4_CttsAtom::Create in Core/Ap4CttsAtom.cpp.

  • CVE-2022-40439MedSep 14, 2022
    risk 0.42cvss 6.5epss 0.01

    An memory leak issue was discovered in AP4_StdcFileByteStream::Create in mp42ts in Bento4 v1.6.0-639, allows attackers to cause a denial of service via a crafted file.

  • CVE-2022-40438MedSep 14, 2022
    risk 0.42cvss 6.5epss 0.01

    Buffer overflow vulnerability in function AP4_MemoryByteStream::WritePartial in mp42aac in Bento4 v1.6.0-639, allows attackers to cause a denial of service via a crafted file.

  • CVE-2020-21066MedAug 13, 2021
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in Bento4 v1.5.1.0. There is a heap-buffer-overflow in AP4_Dec3Atom::AP4_Dec3Atom at Ap4Dec3Atom.cpp, leading to a denial of service (program crash), as demonstrated by mp42aac.

  • CVE-2021-35307MedAug 5, 2021
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in Bento4 through v1.6.0-636. A NULL pointer dereference exists in the AP4_DescriptorFinder::Test component located in /Core/Ap4Descriptor.h. It allows an attacker to cause a denial of service (DOS).

  • CVE-2021-35306MedAug 5, 2021
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in Bento4 through v1.6.0-636. A NULL pointer dereference exists in the function AP4_StszAtom::WriteFields located in Ap4StszAtom.cpp. It allows an attacker to cause a denial of service (DOS).

  • CVE-2020-19722MedJul 13, 2021
    risk 0.42cvss 6.5epss 0.01

    An unhandled memory allocation failure in Core/Ap4Atom.cpp of Bento 1.5.1-628 causes a direct copy to NULL pointer dereference, leading to a denial of service (DOS).

  • CVE-2020-19721MedJul 13, 2021
    risk 0.42cvss 6.5epss 0.01

    A heap buffer overflow vulnerability in Ap4TrunAtom.cpp of Bento 1.5.1-628 may lead to an out-of-bounds write while running mp42aac, leading to system crashes and a denial of service (DOS).

  • CVE-2020-19720MedJul 13, 2021
    risk 0.42cvss 6.5epss 0.01

    An unhandled memory allocation failure in Core/AP4IkmsAtom.cpp of Bento 1.5.1-628 causes a NULL pointer dereference, leading to a denial of service (DOS).

  • CVE-2020-19718MedJul 13, 2021
    risk 0.42cvss 6.5epss 0.01

    An unhandled memory allocation failure in Core/Ap4Atom.cpp of Bento 1.5.1-628 causes a NULL pointer dereference, leading to a denial of service (DOS).

  • CVE-2020-19717MedJul 13, 2021
    risk 0.42cvss 6.5epss 0.01

    An unhandled memory allocation failure in Core/Ap48bdlAtom.cpp of Bento 1.5.1-628 causes a NULL pointer dereference, leading to a denial of service (DOS).

  • CVE-2019-17454MedOct 10, 2019
    risk 0.42cvss 6.5epss 0.01

    Bento4 1.5.1.0 has a NULL pointer dereference in AP4_Descriptor::GetTag in Core/Ap4Descriptor.h, related to AP4_StsdAtom::GetSampleDescription in Core/Ap4StsdAtom.cpp, as demonstrated by mp4info.

  • CVE-2019-17453MedOct 10, 2019
    risk 0.42cvss 6.5epss 0.01

    Bento4 1.5.1.0 has a NULL pointer dereference in AP4_DescriptorListWriter::Action in Core/Ap4Descriptor.h, related to AP4_IodsAtom::WriteFields in Core/Ap4IodsAtom.cpp, as demonstrated by mp4encrypt or mp4compact.

  • CVE-2019-17452MedOct 10, 2019
    risk 0.42cvss 6.5epss 0.01

    Bento4 1.5.1.0 has a NULL pointer dereference in AP4_DescriptorListInspector::Action in Core/Ap4Descriptor.h, related to AP4_IodsAtom::InspectFields in Core/Ap4IodsAtom.cpp, as demonstrated by mp4dump.

Page 5 of 9