Bento4
by Bento4
Source repositories
CVEs (176)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-0751 | Med | 0.41 | 6.3 | 0.00 | Jan 27, 2025 | A vulnerability classified as critical has been found in Axiomatic Bento4 up to 1.6.0. This affects the function AP4_BitReader::ReadBits of the component mp42aac. The manipulation leads to heap-based buffer overflow. It is possible to initiate the attack remotely. The exploit… | ||
| CVE-2022-4584 | Med | 0.41 | 6.3 | 0.01 | Dec 17, 2022 | A vulnerability was found in Axiomatic Bento4 up to 1.6.0-639. It has been rated as critical. Affected by this issue is some unknown functionality of the component mp42aac. The manipulation leads to heap-based buffer overflow. The attack may be launched remotely. The exploit has… | ||
| CVE-2022-3974 | Med | 0.41 | 6.3 | 0.01 | Nov 13, 2022 | A vulnerability classified as critical was found in Axiomatic Bento4. Affected by this vulnerability is the function AP4_StdcFileByteStream::ReadPartial of the file Ap4StdCFileByteStream.cpp of the component mp4info. The manipulation leads to heap-based buffer overflow. The… | ||
| CVE-2022-3785 | Med | 0.41 | 6.3 | 0.01 | Oct 31, 2022 | A vulnerability, which was classified as critical, has been found in Axiomatic Bento4. Affected by this issue is the function AP4_DataBuffer::SetDataSize of the component Avcinfo. The manipulation leads to heap-based buffer overflow. The attack may be launched remotely. The… | ||
| CVE-2022-3784 | Med | 0.41 | 6.3 | 0.01 | Oct 31, 2022 | A vulnerability classified as critical was found in Axiomatic Bento4 5e7bb34. Affected by this vulnerability is the function AP4_Mp4AudioDsiParser::ReadBits of the file Ap4Mp4AudioInfo.cpp of the component mp4hls. The manipulation leads to heap-based buffer overflow. The attack… | ||
| CVE-2025-25947 | Med | 0.36 | 5.5 | 0.00 | Feb 19, 2025 | An issue in Bento4 v1.6.0-641 allows an attacker to trigger a segmentation fault via Ap4Atom.cpp, specifically in AP4_AtomParent::RemoveChild, during the execution of mp4encrypt with a specially crafted MP4 input file. | ||
| CVE-2025-25946 | Med | 0.36 | 5.5 | 0.00 | Feb 19, 2025 | An issue in Bento4 v1.6.0-641 allows an attacker to cause a memory leak via Ap4Marlin.cpp and Ap4Processor.cpp, specifically in AP4_MarlinIpmpEncryptingProcessor::Initialize and AP4_Processor::Process, during the execution of mp4encrypt with a specially crafted MP4 input file. | ||
| CVE-2025-0870 | Med | 0.36 | 5.6 | 0.01 | Jan 30, 2025 | A vulnerability was found in Axiomatic Bento4 up to 1.6.0-641. It has been rated as critical. Affected by this issue is the function AP4_DataBuffer::GetData in the library Ap4DataBuffer.h. The manipulation leads to heap-based buffer overflow. The attack may be launched remotely.… | ||
| CVE-2024-25454 | Med | 0.36 | 5.5 | 0.00 | Feb 9, 2024 | Bento4 v1.6.0-640 was discovered to contain a NULL pointer dereference via the AP4_DescriptorFinder::Test() function. | ||
| CVE-2024-25453 | Med | 0.36 | 5.5 | 0.00 | Feb 9, 2024 | Bento4 v1.6.0-640 was discovered to contain a NULL pointer dereference via the AP4_StszAtom::GetSampleSize() function. | ||
| CVE-2024-25452 | Med | 0.36 | 5.5 | 0.00 | Feb 9, 2024 | Bento4 v1.6.0-640 was discovered to contain an out-of-memory bug via the AP4_UrlAtom::AP4_UrlAtom() function. | ||
| CVE-2023-38666 | Med | 0.36 | 5.5 | 0.00 | Aug 22, 2023 | Bento4 v1.6.0-639 was discovered to contain a segmentation violation via the AP4_Processor::ProcessFragments function in mp4encrypt. | ||
| CVE-2023-29575 | Med | 0.36 | 5.5 | 0.00 | Apr 21, 2023 | Bento4 v1.6.0-639 was discovered to contain an out-of-memory bug in the mp42aac component. | ||
| CVE-2023-29573 | Med | 0.36 | 5.5 | 0.00 | Apr 13, 2023 | Bento4 v1.6.0-639 was discovered to contain an out-of-memory bug in the mp4info component. | ||
| CVE-2023-29574 | Med | 0.36 | 5.5 | 0.00 | Apr 12, 2023 | Bento4 v1.6.0-639 was discovered to contain an out-of-memory bug in the mp42avc component. | ||
| CVE-2023-29576 | Med | 0.36 | 5.5 | 0.00 | Apr 11, 2023 | Bento4 v1.6.0-639 was discovered to contain a segmentation violation via the AP4_TrunAtom::SetDataOffset(int) function in Ap4TrunAtom.h. | ||
| CVE-2022-40885 | Med | 0.36 | 5.5 | 0.00 | Oct 19, 2022 | Bento4 v1.6.0-639 has a memory allocation issue that can cause denial of service. | ||
| CVE-2022-40884 | Med | 0.36 | 5.5 | 0.00 | Oct 19, 2022 | Bento4 1.6.0 has memory leaks via the mp4fragment. | ||
| CVE-2022-41847 | Med | 0.36 | 5.5 | 0.00 | Sep 30, 2022 | An issue was discovered in Bento4 1.6.0-639. A memory leak exists in AP4_StdcFileByteStream::Create(AP4_FileByteStream*, char const*, AP4_FileByteStream::Mode, AP4_ByteStream*&) in System/StdC/Ap4StdCFileByteStream.cpp. | ||
| CVE-2022-41846 | Med | 0.36 | 5.5 | 0.00 | Sep 30, 2022 | An issue was discovered in Bento4 1.6.0-639. There ie excessive memory consumption in the function AP4_DataBuffer::ReallocateBuffer in Core/Ap4DataBuffer.cpp. |
- risk 0.41cvss 6.3epss 0.00
A vulnerability classified as critical has been found in Axiomatic Bento4 up to 1.6.0. This affects the function AP4_BitReader::ReadBits of the component mp42aac. The manipulation leads to heap-based buffer overflow. It is possible to initiate the attack remotely. The exploit…
- risk 0.41cvss 6.3epss 0.01
A vulnerability was found in Axiomatic Bento4 up to 1.6.0-639. It has been rated as critical. Affected by this issue is some unknown functionality of the component mp42aac. The manipulation leads to heap-based buffer overflow. The attack may be launched remotely. The exploit has…
- risk 0.41cvss 6.3epss 0.01
A vulnerability classified as critical was found in Axiomatic Bento4. Affected by this vulnerability is the function AP4_StdcFileByteStream::ReadPartial of the file Ap4StdCFileByteStream.cpp of the component mp4info. The manipulation leads to heap-based buffer overflow. The…
- risk 0.41cvss 6.3epss 0.01
A vulnerability, which was classified as critical, has been found in Axiomatic Bento4. Affected by this issue is the function AP4_DataBuffer::SetDataSize of the component Avcinfo. The manipulation leads to heap-based buffer overflow. The attack may be launched remotely. The…
- risk 0.41cvss 6.3epss 0.01
A vulnerability classified as critical was found in Axiomatic Bento4 5e7bb34. Affected by this vulnerability is the function AP4_Mp4AudioDsiParser::ReadBits of the file Ap4Mp4AudioInfo.cpp of the component mp4hls. The manipulation leads to heap-based buffer overflow. The attack…
- risk 0.36cvss 5.5epss 0.00
An issue in Bento4 v1.6.0-641 allows an attacker to trigger a segmentation fault via Ap4Atom.cpp, specifically in AP4_AtomParent::RemoveChild, during the execution of mp4encrypt with a specially crafted MP4 input file.
- risk 0.36cvss 5.5epss 0.00
An issue in Bento4 v1.6.0-641 allows an attacker to cause a memory leak via Ap4Marlin.cpp and Ap4Processor.cpp, specifically in AP4_MarlinIpmpEncryptingProcessor::Initialize and AP4_Processor::Process, during the execution of mp4encrypt with a specially crafted MP4 input file.
- risk 0.36cvss 5.6epss 0.01
A vulnerability was found in Axiomatic Bento4 up to 1.6.0-641. It has been rated as critical. Affected by this issue is the function AP4_DataBuffer::GetData in the library Ap4DataBuffer.h. The manipulation leads to heap-based buffer overflow. The attack may be launched remotely.…
- risk 0.36cvss 5.5epss 0.00
Bento4 v1.6.0-640 was discovered to contain a NULL pointer dereference via the AP4_DescriptorFinder::Test() function.
- risk 0.36cvss 5.5epss 0.00
Bento4 v1.6.0-640 was discovered to contain a NULL pointer dereference via the AP4_StszAtom::GetSampleSize() function.
- risk 0.36cvss 5.5epss 0.00
Bento4 v1.6.0-640 was discovered to contain an out-of-memory bug via the AP4_UrlAtom::AP4_UrlAtom() function.
- risk 0.36cvss 5.5epss 0.00
Bento4 v1.6.0-639 was discovered to contain a segmentation violation via the AP4_Processor::ProcessFragments function in mp4encrypt.
- risk 0.36cvss 5.5epss 0.00
Bento4 v1.6.0-639 was discovered to contain an out-of-memory bug in the mp42aac component.
- risk 0.36cvss 5.5epss 0.00
Bento4 v1.6.0-639 was discovered to contain an out-of-memory bug in the mp4info component.
- risk 0.36cvss 5.5epss 0.00
Bento4 v1.6.0-639 was discovered to contain an out-of-memory bug in the mp42avc component.
- risk 0.36cvss 5.5epss 0.00
Bento4 v1.6.0-639 was discovered to contain a segmentation violation via the AP4_TrunAtom::SetDataOffset(int) function in Ap4TrunAtom.h.
- risk 0.36cvss 5.5epss 0.00
Bento4 v1.6.0-639 has a memory allocation issue that can cause denial of service.
- risk 0.36cvss 5.5epss 0.00
Bento4 1.6.0 has memory leaks via the mp4fragment.
- risk 0.36cvss 5.5epss 0.00
An issue was discovered in Bento4 1.6.0-639. A memory leak exists in AP4_StdcFileByteStream::Create(AP4_FileByteStream*, char const*, AP4_FileByteStream::Mode, AP4_ByteStream*&) in System/StdC/Ap4StdCFileByteStream.cpp.
- risk 0.36cvss 5.5epss 0.00
An issue was discovered in Bento4 1.6.0-639. There ie excessive memory consumption in the function AP4_DataBuffer::ReallocateBuffer in Core/Ap4DataBuffer.cpp.
Page 7 of 9