VYPR

Vendor CVEs

Bento4

All CVEs

176 total · sorted by risk
  • CVE-2024-31004CriApr 2, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the Ap4StsdAtom.cpp,AP4_StsdAtom::AP4_StsdAtom,mp4fragment.

  • CVE-2024-31002CriApr 2, 2024
    risk 0.64cvss 9.8epss 0.01

    Buffer Overflow vulnerability in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the AP4 BitReader::ReadCache() at Ap4Utils.cpp component.

  • CVE-2018-14532CriJul 23, 2018
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in Bento4 1.5.1-624. There is a heap-based buffer over-read in AP4_Mpeg2TsVideoSampleStream::WriteSample in Core/Ap4Mpeg2Ts.cpp after a call from Mp42Hls.cpp, a related issue to CVE-2018-13846.

  • CVE-2018-14531CriJul 23, 2018
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in Bento4 1.5.1-624. There is an unspecified "heap-buffer-overflow" crash in the AP4_HvccAtom class in Core/Ap4HvccAtom.cpp.

  • CVE-2018-13846CriJul 10, 2018
    risk 0.64cvss 9.8epss 0.02

    An issue has been found in Bento4 1.5.1-624. AP4_Mpeg2TsVideoSampleStream::WriteSample in Core/Ap4Mpeg2Ts.cpp has a heap-based buffer over-read after a call from Mp42Ts.cpp, a related issue to CVE-2018-14532.

  • CVE-2024-31003HigApr 2, 2024
    risk 0.57cvss 8.8epss 0.01

    Buffer Overflow vulnerability in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the AP4_MemoryByteStream::WritePartial at Ap4ByteStream.cpp.

  • CVE-2022-41430HigOct 3, 2022
    risk 0.57cvss 8.8epss 0.01

    Bento4 v1.6.0-639 was discovered to contain a heap overflow via the AP4_BitReader::ReadBit function in mp4mux.

  • CVE-2022-41429HigOct 3, 2022
    risk 0.57cvss 8.8epss 0.01

    Bento4 v1.6.0-639 was discovered to contain a heap overflow via the AP4_Atom::TypeFromString function in mp4tag.

  • CVE-2022-41428HigOct 3, 2022
    risk 0.57cvss 8.8epss 0.01

    Bento4 v1.6.0-639 was discovered to contain a heap overflow via the AP4_BitReader::ReadBits function in mp4mux.

  • CVE-2021-32265HigSep 20, 2021
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in Bento4 through v1.6.0-637. A global-buffer-overflow exists in the function AP4_MemoryByteStream::WritePartial() located in Ap4ByteStream.cpp. It allows an attacker to cause code execution or information disclosure.

  • CVE-2019-15050HigAug 14, 2019
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer over-read in the AP4_AvccAtom class at Core/Ap4AvccAtom.cpp.

  • CVE-2019-15049HigAug 14, 2019
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer over-read in the AP4_Dec3Atom class at Core/Ap4Dec3Atom.cpp.

  • CVE-2019-15048HigAug 14, 2019
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer overflow in the AP4_RtpAtom class at Core/Ap4RtpAtom.cpp.

  • CVE-2019-15047HigAug 14, 2019
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer over-read in the function AP4_BitReader::SkipBits at Core/Ap4Utils.cpp.

  • CVE-2019-9544HigMar 1, 2019
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in Bento4 1.5.1-628. An out of bounds write occurs in AP4_CttsTableEntry::AP4_CttsTableEntry() located in Core/Ap4Array.h. It can be triggered by sending a crafted file to (for example) the mp42hls binary. It allows an attacker to cause Denial of Service…

  • CVE-2019-8382HigFeb 17, 2019
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in Bento4 1.5.1-628. A NULL pointer dereference occurs in the function AP4_List:Find located in Core/Ap4List.h when called from Core/Ap4Movie.cpp. It can be triggered by sending a crafted file to the mp4dump binary. It allows an attacker to cause a Denial…

  • CVE-2019-8380HigFeb 17, 2019
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in Bento4 1.5.1-628. A NULL pointer dereference occurs in AP4_Track::GetSampleIndexForTimeStampMs() located in Core/Ap4Track.cpp. It can triggered by sending a crafted file to the mp4audioclip binary. It allows an attacker to cause a Denial of Service…

  • CVE-2019-8378HigFeb 17, 2019
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in Bento4 1.5.1-628. A heap-based buffer over-read exists in AP4_BitStream::ReadBytes() in Codecs/Ap4BitStream.cpp, a similar issue to CVE-2017-14645. It can be triggered by sending a crafted file to the aac2mp4 binary. It allows an attacker to cause a…

  • CVE-2018-14589HigJul 24, 2018
    risk 0.57cvss 8.8epss 0.01

    An issue has been discovered in Bento4 1.5.1-624. AP4_Mp4AudioDsiParser::ReadBits in Codecs/Ap4Mp4AudioInfo.cpp has a heap-based buffer over-read.

  • CVE-2018-14587HigJul 24, 2018
    risk 0.57cvss 8.8epss 0.01

    An issue has been discovered in Bento4 1.5.1-624. AP4_MemoryByteStream::WritePartial in Core/Ap4ByteStream.cpp has a buffer over-read.

  • CVE-2018-14586HigJul 24, 2018
    risk 0.57cvss 8.8epss 0.01

    An issue has been discovered in Bento4 1.5.1-624. A SEGV can occur in AP4_Mpeg2TsAudioSampleStream::WriteSample in Core/Ap4Mpeg2Ts.cpp, a different vulnerability than CVE-2018-14532.

  • CVE-2018-14585HigJul 24, 2018
    risk 0.57cvss 8.8epss 0.01

    An issue has been discovered in Bento4 1.5.1-624. AP4_BytesToUInt16BE in Core/Ap4Utils.h has a heap-based buffer over-read after a call from the AP4_Stz2Atom class.

  • CVE-2018-14584HigJul 24, 2018
    risk 0.57cvss 8.8epss 0.02

    An issue has been discovered in Bento4 1.5.1-624. AP4_AvccAtom::Create in Core/Ap4AvccAtom.cpp has a heap-based buffer over-read.

  • CVE-2017-14647HigSep 21, 2017
    risk 0.57cvss 8.8epss 0.02

    A heap-based buffer overflow was discovered in AP4_VisualSampleEntry::ReadFields in Core/Ap4SampleEntry.cpp in Bento4 1.5.0-617. The vulnerability causes an out-of-bounds write, which leads to remote denial of service or possibly code execution.

  • CVE-2017-14644HigSep 21, 2017
    risk 0.57cvss 8.8epss 0.02

    A heap-based buffer overflow was discovered in the AP4_HdlrAtom class in Bento4 1.5.0-617. The vulnerability causes an out-of-bounds write, which leads to remote denial of service or possibly code execution.

  • CVE-2017-14639HigSep 21, 2017
    risk 0.57cvss 8.8epss 0.02

    AP4_VisualSampleEntry::ReadFields in Core/Ap4SampleEntry.cpp in Bento4 1.5.0-617 uses incorrect character data types, which causes a stack-based buffer underflow and out-of-bounds write, leading to denial of service (application crash) or possibly unspecified other impact.

  • CVE-2024-31005HigApr 2, 2024
    risk 0.53cvss 8.1epss 0.01

    An issue in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the Ap4MdhdAtom.cpp,AP4_MdhdAtom::AP4_MdhdAtom,mp4fragment

  • CVE-2022-27607HigMar 21, 2022
    risk 0.53cvss 8.1epss 0.01

    Bento4 1.6.0-639 has a heap-based buffer over-read in the AP4_HvccAtom class, a different issue than CVE-2018-14531.

  • CVE-2025-25943HigFeb 19, 2025
    risk 0.51cvss 7.8epss 0.00

    Buffer Overflow vulnerability in Bento4 v.1.6.0-641 allows a local attacker to execute arbitrary code via the AP4_Stz2Atom::AP4_Stz2Atom component located in Ap4Stz2Atom.cpp.

  • CVE-2024-57510HigJan 29, 2025
    risk 0.51cvss 7.8epss 0.00

    Buffer Overflow vulnerability in Bento4 mp42avc v.3bdc891602d19789b8e8626e4a3e613a937b4d35 allows a local attacker to execute arbitrary code via the AP4_MemoryByteStream::WritePartial.

  • CVE-2024-57509HigJan 29, 2025
    risk 0.51cvss 7.8epss 0.00

    Buffer Overflow vulnerability in Bento4 mp42avc v.3bdc891602d19789b8e8626e4a3e613a937b4d35 allows a local attacker to execute arbitrary code via the AP4_File::ParseStream and related functions.

  • CVE-2019-20090HigDec 30, 2019
    risk 0.51cvss 7.8epss 0.01

    An issue was discovered in Bento4 1.5.1.0. There is a use-after-free in AP4_Sample::GetOffset in Core/Ap4Sample.h when called from Ap4LinearReader.cpp.

  • CVE-2019-17530HigOct 12, 2019
    risk 0.51cvss 7.8epss 0.01

    An issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer over-read in AP4_PrintInspector::AddField in Core/Ap4Atom.cpp when called from AP4_CencSampleEncryption::DoInspectFields in Core/Ap4CommonEncryption.cpp, when called from AP4_Atom::Inspect in…

  • CVE-2019-17529HigOct 12, 2019
    risk 0.51cvss 7.8epss 0.01

    An issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer over-read in AP4_CencSampleEncryption::DoInspectFields in Core/Ap4CommonEncryption.cpp when called from AP4_Atom::Inspect in Core/Ap4Atom.cpp.

  • CVE-2018-5253HigJan 5, 2018
    risk 0.51cvss 7.8epss 0.01

    The AP4_FtypAtom class in Core/Ap4FtypAtom.cpp in Bento4 1.5.1.0 has an Infinite loop via a crafted MP4 file that triggers size mishandling.

  • CVE-2017-14261HigSep 11, 2017
    risk 0.51cvss 7.8epss 0.01

    In the SDK in Bento4 1.5.0-616, the AP4_StszAtom class in Ap4StszAtom.cpp file contains a Read Memory Access Violation vulnerability. It is possible to exploit this vulnerability by opening a crafted .MP4 file.

  • CVE-2017-14260HigSep 11, 2017
    risk 0.51cvss 7.8epss 0.01

    In the SDK in Bento4 1.5.0-616, the AP4_StssAtom class in Ap4StssAtom.cpp contains a Write Memory Access Violation vulnerability. It is possible to exploit this vulnerability and possibly execute arbitrary code by opening a crafted .MP4 file.

  • CVE-2017-14259HigSep 11, 2017
    risk 0.51cvss 7.8epss 0.01

    In the SDK in Bento4 1.5.0-616, the AP4_StscAtom class in Ap4StscAtom.cpp contains a Write Memory Access Violation vulnerability. It is possible to exploit this vulnerability and possibly execute arbitrary code by opening a crafted .MP4 file.

  • CVE-2017-14258HigSep 11, 2017
    risk 0.51cvss 7.8epss 0.01

    In the SDK in Bento4 1.5.0-616, SetItemCount in Core/Ap4StscAtom.h file contains a Write Memory Access Violation vulnerability. It is possible to exploit this vulnerability and possibly execute arbitrary code by opening a crafted .MP4 file.

  • CVE-2017-14257HigSep 11, 2017
    risk 0.51cvss 7.8epss 0.01

    In the SDK in Bento4 1.5.0-616, AP4_AtomSampleTable::GetSample in Core/Ap4AtomSampleTable.cpp contains a Read Memory Access Violation vulnerability. It is possible to exploit this vulnerability by opening a crafted .MP4 file.

  • CVE-2024-30809HigApr 2, 2024
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Bento4 v1.6.0-641-2-g1529b83. There is a heap-use-after-free in Ap4Sample.h in AP4_Sample::GetOffset() const, leading to a Denial of Service (DoS), as demonstrated by mp42ts.

  • CVE-2024-30807HigApr 2, 2024
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Bento4 v1.6.0-641-2-g1529b83. There is a heap-use-after-free in AP4_UnknownAtom::~AP4_UnknownAtom at Ap4Atom.cpp, leading to a Denial of Service (DoS), as demonstrated by mp42ts.

  • CVE-2021-40941HigJun 27, 2022
    risk 0.49cvss 7.5epss 0.01

    In Bento4 1.6.0-638, there is an allocator is out of memory in the function AP4_Array<AP4_TrunAtom::Entry>::EnsureCapacity in Ap4Array.h:172, as demonstrated by GPAC. This can cause a denial of service (DOS).

  • CVE-2018-10790HigAug 25, 2021
    risk 0.49cvss 7.5epss 0.02

    The AP4_CttsAtom class in Core/Ap4CttsAtom.cpp in Bento4 1.5.1.0 allows remote attackers to cause a denial of service (application crash), related to a memory allocation failure, as demonstrated by mp2aac.

  • CVE-2020-23334HigAug 17, 2021
    risk 0.49cvss 7.5epss 0.01

    A WRITE memory access in the AP4_NullTerminatedStringAtom::AP4_NullTerminatedStringAtom component of Bento4 version 06c39d9 can lead to a segmentation fault.

  • CVE-2020-23333HigAug 17, 2021
    risk 0.49cvss 7.5epss 0.01

    A heap-based buffer overflow exists in the AP4_CttsAtom::AP4_CttsAtom component located in /Core/Ap4Utils.h of Bento4 version 06c39d9. This can lead to a denial of service (DOS).

  • CVE-2020-23332HigAug 17, 2021
    risk 0.49cvss 7.5epss 0.01

    A heap-based buffer overflow exists in the AP4_StdcFileByteStream::ReadPartial component located in /StdC/Ap4StdCFileByteStream.cpp of Bento4 version 06c39d9. This issue can lead to a denial of service (DOS).

  • CVE-2020-23331HigAug 17, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Bento4 version 06c39d9. A NULL pointer dereference exists in the AP4_DescriptorListWriter::Action component located in /Core/Ap4Descriptor.h. It allows an attacker to cause a denial of service (DOS).

  • CVE-2020-23330HigAug 17, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Bento4 version 06c39d9. A NULL pointer dereference exists in the AP4_Stz2Atom::GetSampleSize component located in /Core/Ap4Stz2Atom.cpp. It allows an attacker to cause a denial of service (DOS).

  • CVE-2019-17528HigOct 12, 2019
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Bento4 1.5.1.0. There is a SEGV in the function AP4_TfhdAtom::SetDefaultSampleSize at Core/Ap4TfhdAtom.h when called from AP4_Processor::ProcessFragments in Core/Ap4Processor.cpp.

Page 1 of 4