VYPR

Bento4

by Bento4

Source repositories

CVEs (176)

  • CVE-2025-0751MedJan 27, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability classified as critical has been found in Axiomatic Bento4 up to 1.6.0. This affects the function AP4_BitReader::ReadBits of the component mp42aac. The manipulation leads to heap-based buffer overflow. It is possible to initiate the attack remotely. The exploit…

  • CVE-2022-4584MedDec 17, 2022
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in Axiomatic Bento4 up to 1.6.0-639. It has been rated as critical. Affected by this issue is some unknown functionality of the component mp42aac. The manipulation leads to heap-based buffer overflow. The attack may be launched remotely. The exploit has…

  • CVE-2022-3974MedNov 13, 2022
    risk 0.41cvss 6.3epss 0.01

    A vulnerability classified as critical was found in Axiomatic Bento4. Affected by this vulnerability is the function AP4_StdcFileByteStream::ReadPartial of the file Ap4StdCFileByteStream.cpp of the component mp4info. The manipulation leads to heap-based buffer overflow. The…

  • CVE-2022-3785MedOct 31, 2022
    risk 0.41cvss 6.3epss 0.01

    A vulnerability, which was classified as critical, has been found in Axiomatic Bento4. Affected by this issue is the function AP4_DataBuffer::SetDataSize of the component Avcinfo. The manipulation leads to heap-based buffer overflow. The attack may be launched remotely. The…

  • CVE-2022-3784MedOct 31, 2022
    risk 0.41cvss 6.3epss 0.01

    A vulnerability classified as critical was found in Axiomatic Bento4 5e7bb34. Affected by this vulnerability is the function AP4_Mp4AudioDsiParser::ReadBits of the file Ap4Mp4AudioInfo.cpp of the component mp4hls. The manipulation leads to heap-based buffer overflow. The attack…

  • CVE-2025-25947MedFeb 19, 2025
    risk 0.36cvss 5.5epss 0.00

    An issue in Bento4 v1.6.0-641 allows an attacker to trigger a segmentation fault via Ap4Atom.cpp, specifically in AP4_AtomParent::RemoveChild, during the execution of mp4encrypt with a specially crafted MP4 input file.

  • CVE-2025-25946MedFeb 19, 2025
    risk 0.36cvss 5.5epss 0.00

    An issue in Bento4 v1.6.0-641 allows an attacker to cause a memory leak via Ap4Marlin.cpp and Ap4Processor.cpp, specifically in AP4_MarlinIpmpEncryptingProcessor::Initialize and AP4_Processor::Process, during the execution of mp4encrypt with a specially crafted MP4 input file.

  • CVE-2025-0870MedJan 30, 2025
    risk 0.36cvss 5.6epss 0.01

    A vulnerability was found in Axiomatic Bento4 up to 1.6.0-641. It has been rated as critical. Affected by this issue is the function AP4_DataBuffer::GetData in the library Ap4DataBuffer.h. The manipulation leads to heap-based buffer overflow. The attack may be launched remotely.…

  • CVE-2024-25454MedFeb 9, 2024
    risk 0.36cvss 5.5epss 0.00

    Bento4 v1.6.0-640 was discovered to contain a NULL pointer dereference via the AP4_DescriptorFinder::Test() function.

  • CVE-2024-25453MedFeb 9, 2024
    risk 0.36cvss 5.5epss 0.00

    Bento4 v1.6.0-640 was discovered to contain a NULL pointer dereference via the AP4_StszAtom::GetSampleSize() function.

  • CVE-2024-25452MedFeb 9, 2024
    risk 0.36cvss 5.5epss 0.00

    Bento4 v1.6.0-640 was discovered to contain an out-of-memory bug via the AP4_UrlAtom::AP4_UrlAtom() function.

  • CVE-2023-38666MedAug 22, 2023
    risk 0.36cvss 5.5epss 0.00

    Bento4 v1.6.0-639 was discovered to contain a segmentation violation via the AP4_Processor::ProcessFragments function in mp4encrypt.

  • CVE-2023-29575MedApr 21, 2023
    risk 0.36cvss 5.5epss 0.00

    Bento4 v1.6.0-639 was discovered to contain an out-of-memory bug in the mp42aac component.

  • CVE-2023-29573MedApr 13, 2023
    risk 0.36cvss 5.5epss 0.00

    Bento4 v1.6.0-639 was discovered to contain an out-of-memory bug in the mp4info component.

  • CVE-2023-29574MedApr 12, 2023
    risk 0.36cvss 5.5epss 0.00

    Bento4 v1.6.0-639 was discovered to contain an out-of-memory bug in the mp42avc component.

  • CVE-2023-29576MedApr 11, 2023
    risk 0.36cvss 5.5epss 0.00

    Bento4 v1.6.0-639 was discovered to contain a segmentation violation via the AP4_TrunAtom::SetDataOffset(int) function in Ap4TrunAtom.h.

  • CVE-2022-40885MedOct 19, 2022
    risk 0.36cvss 5.5epss 0.00

    Bento4 v1.6.0-639 has a memory allocation issue that can cause denial of service.

  • CVE-2022-40884MedOct 19, 2022
    risk 0.36cvss 5.5epss 0.00

    Bento4 1.6.0 has memory leaks via the mp4fragment.

  • CVE-2022-41847MedSep 30, 2022
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in Bento4 1.6.0-639. A memory leak exists in AP4_StdcFileByteStream::Create(AP4_FileByteStream*, char const*, AP4_FileByteStream::Mode, AP4_ByteStream*&) in System/StdC/Ap4StdCFileByteStream.cpp.

  • CVE-2022-41846MedSep 30, 2022
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in Bento4 1.6.0-639. There ie excessive memory consumption in the function AP4_DataBuffer::ReallocateBuffer in Core/Ap4DataBuffer.cpp.

Page 7 of 9