VYPR

Bento4

by Bento4

Source repositories

CVEs (176)

  • CVE-2022-41845MedSep 30, 2022
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in Bento4 1.6.0-639. There ie excessive memory consumption in the function AP4_Array<AP4_ElstEntry>::EnsureCapacity in Core/Ap4Array.h.

  • CVE-2022-41841MedSep 30, 2022
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in Bento4 through 1.6.0-639. A NULL pointer dereference occurs in AP4_File::ParseStream in Core/Ap4File.cpp, which is called from AP4_File::AP4_File.

  • CVE-2022-40775MedSep 18, 2022
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in Bento4 through 1.6.0-639. A NULL pointer dereference occurs in AP4_StszAtom::WriteFields.

  • CVE-2022-40774MedSep 18, 2022
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in Bento4 through 1.6.0-639. There is a NULL pointer dereference in AP4_StszAtom::GetSampleSize.

  • CVE-2022-35165MedAug 18, 2022
    risk 0.36cvss 5.5epss 0.00

    An issue in AP4_SgpdAtom::AP4_SgpdAtom() of Bento4-1.6.0-639 allows attackers to cause a Denial of Service (DoS) via a crafted mp4 input.

  • CVE-2021-40943MedJun 28, 2022
    risk 0.36cvss 5.5epss 0.01

    In Bento4 1.6.0-638, there is a null pointer reference in the function AP4_DescriptorListInspector::Action function in Ap4Descriptor.h:124 , as demonstrated by GPAC. This can cause a denial of service (DOS).

  • CVE-2022-31287MedJun 10, 2022
    risk 0.36cvss 5.5epss 0.01

    An issue was discovered in Bento4 v1.2. There is an allocation size request error in /Ap4RtpAtom.cpp.

  • CVE-2022-31285MedJun 10, 2022
    risk 0.36cvss 5.5epss 0.01

    An issue was discovered in Bento4 1.2. The allocator is out of memory in /Source/C++/Core/Ap4Array.h.

  • CVE-2022-31282MedJun 10, 2022
    risk 0.36cvss 5.5epss 0.01

    Bento4 MP4Dump v1.2 was discovered to contain a segmentation violation via an unknown address at /Source/C++/Core/Ap4DataBuffer.cpp:175.

  • CVE-2022-29017MedMay 16, 2022
    risk 0.36cvss 5.5epss 0.01

    Bento4 v1.6.0.0 was discovered to contain a segmentation fault via the component /x86_64/multiarch/strlen-avx2.S.

  • CVE-2020-23912MedApr 21, 2021
    risk 0.36cvss 5.5epss 0.01

    An issue was discovered in Bento4 through v1.6.0-637. A NULL pointer dereference exists in the function AP4_StszAtom::GetSampleSize() located in Ap4StszAtom.cpp. It allows an attacker to cause Denial of Service.

  • CVE-2019-20092MedDec 30, 2019
    risk 0.36cvss 5.5epss 0.01

    An issue was discovered in Bento4 1.5.1.0. There is a NULL pointer dereference in AP4_Descriptor::GetTag in mp42ts when called from AP4_EsDescriptor::GetDecoderConfigDescriptor in Ap4EsDescriptor.cpp.

  • CVE-2019-20091MedDec 30, 2019
    risk 0.36cvss 5.5epss 0.01

    An issue was discovered in Bento4 1.5.1.0. There is a NULL pointer dereference in AP4_Descriptor::GetTag in mp42ts when called from AP4_DecoderConfigDescriptor::GetDecoderSpecificInfoDescriptor in Ap4DecoderConfigDescriptor.cpp.

  • CVE-2019-16349MedSep 16, 2019
    risk 0.36cvss 5.5epss 0.01

    Bento4 1.5.1-628 has a NULL pointer dereference in AP4_ByteStream::ReadUI32 in Core/Ap4ByteStream.cpp when called from the AP4_TrunAtom class.

  • CVE-2018-14545MedJul 23, 2018
    risk 0.36cvss 5.5epss 0.01

    There exists one invalid memory read bug in AP4_SampleDescription::GetType() in Ap4SampleDescription.h in Bento4 1.5.1-624, which can allow attackers to cause a denial-of-service via a crafted mp4 file. This vulnerability can be triggered by the executable mp42ts.

  • CVE-2018-14544MedJul 23, 2018
    risk 0.36cvss 5.5epss 0.01

    There exists one invalid memory read bug in AP4_SampleDescription::GetFormat() in Ap4SampleDescription.h in Bento4 1.5.1-624, which can allow attackers to cause a denial-of-service via a crafted mp4 file. This vulnerability can be triggered by the executable mp42ts.

  • CVE-2018-14543MedJul 23, 2018
    risk 0.36cvss 5.5epss 0.01

    There exists one NULL pointer dereference vulnerability in AP4_JsonInspector::AddField in Ap4Atom.cpp in Bento4 1.5.1-624, which can allow attackers to cause a denial-of-service via a crafted mp4 file. This vulnerability can be triggered by the executable mp4dump.

  • CVE-2017-12476MedSep 6, 2017
    risk 0.36cvss 5.5epss 0.01

    The AP4_AvccAtom::InspectFields function in Core/Ap4AvccAtom.cpp in Bento4 mp4dump before 1.5.0-616 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted mp4 file.

  • CVE-2017-12475MedSep 6, 2017
    risk 0.36cvss 5.5epss 0.01

    The AP4_Processor::Process function in Core/Ap4Processor.cpp in Bento4 mp4encrypt before 1.5.0-616 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted mp4 file.

  • CVE-2017-12474MedSep 6, 2017
    risk 0.36cvss 5.5epss 0.01

    The AP4_AtomSampleTable::GetSample function in Core/Ap4AtomSampleTable.cpp in Bento4 mp42ts before 1.5.0-616 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted mp4 file.

Page 8 of 9