Vendor CVEs
Bento4
All CVEs
169 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-25942 | 0.00 | — | 0.00 | Feb 19, 2025 | An issue in Bento4 v1.6.0-641 allows an attacker to obtain sensitive information via the the mp4fragment tool when processing invalid files. Specifically, memory allocated in SampleArray::SampleArray in Mp4Fragment.cpp is not properly released. | |||
| CVE-2024-57598 | 0.00 | — | 0.00 | Feb 5, 2025 | A floating point exception (divide-by-zero) vulnerability was discovered in Bento4 1.6.0-641 in function AP4_TfraAtom() of Ap4TfraAtom.cpp which allows a remote attacker to cause a denial of service vulnerability. | |||
| CVE-2025-0870 | 0.00 | — | 0.01 | Jan 30, 2025 | A vulnerability was found in Axiomatic Bento4 up to 1.6.0-641. It has been rated as critical. Affected by this issue is the function AP4_DataBuffer::GetData in the library Ap4DataBuffer.h. The manipulation leads to heap-based buffer overflow. The attack may be launched remotely.… | |||
| CVE-2025-0753 | 0.00 | — | 0.00 | Jan 27, 2025 | A vulnerability classified as critical was found in Axiomatic Bento4 up to 1.6.0. This vulnerability affects the function AP4_StdcFileByteStream::ReadPartial of the component mp42aac. The manipulation leads to heap-based buffer overflow. The attack can be initiated remotely. The… | |||
| CVE-2025-0751 | 0.00 | — | 0.00 | Jan 27, 2025 | A vulnerability classified as critical has been found in Axiomatic Bento4 up to 1.6.0. This affects the function AP4_BitReader::ReadBits of the component mp42aac. The manipulation leads to heap-based buffer overflow. It is possible to initiate the attack remotely. The exploit… | |||
| CVE-2024-30808 | 0.00 | — | 0.01 | Apr 2, 2024 | An issue was discovered in Bento4 v1.6.0-641-2-g1529b83. There is a heap-use-after-free in AP4_SubStream::~AP4_SubStream at Ap4ByteStream.cpp, leading to a Denial of Service (DoS), as demonstrated by mp42ts. | |||
| CVE-2024-31004 | 0.00 | — | 0.01 | Apr 2, 2024 | An issue in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the Ap4StsdAtom.cpp,AP4_StsdAtom::AP4_StsdAtom,mp4fragment. | |||
| CVE-2024-30807 | 0.00 | — | 0.01 | Apr 2, 2024 | An issue was discovered in Bento4 v1.6.0-641-2-g1529b83. There is a heap-use-after-free in AP4_UnknownAtom::~AP4_UnknownAtom at Ap4Atom.cpp, leading to a Denial of Service (DoS), as demonstrated by mp42ts. | |||
| CVE-2024-30809 | 0.00 | — | 0.01 | Apr 2, 2024 | An issue was discovered in Bento4 v1.6.0-641-2-g1529b83. There is a heap-use-after-free in Ap4Sample.h in AP4_Sample::GetOffset() const, leading to a Denial of Service (DoS), as demonstrated by mp42ts. | |||
| CVE-2024-30806 | 0.00 | — | 0.01 | Apr 2, 2024 | An issue was discovered in Bento4 v1.6.0-641-2-g1529b83. There is a heap overflow in AP4_Dec3Atom::AP4_Dec3Atom at Ap4Dec3Atom.cpp, leading to a Denial of Service (DoS), as demonstrated by mp42aac. | |||
| CVE-2024-24155 | 0.00 | — | 0.01 | Feb 28, 2024 | Bento4 v1.5.1-628 contains a Memory leak on AP4_Movie::AP4_Movie, parsing tracks and added into m_Tracks list, but mp42aac cannot correctly delete when we got an no audio track found error. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted mp4… | |||
| CVE-2024-25454 | 0.00 | — | 0.00 | Feb 9, 2024 | Bento4 v1.6.0-640 was discovered to contain a NULL pointer dereference via the AP4_DescriptorFinder::Test() function. | |||
| CVE-2024-25451 | 0.00 | — | 0.01 | Feb 9, 2024 | Bento4 v1.6.0-640 was discovered to contain an out-of-memory bug via the AP4_DataBuffer::ReallocateBuffer() function. | |||
| CVE-2024-25452 | 0.00 | — | 0.00 | Feb 9, 2024 | Bento4 v1.6.0-640 was discovered to contain an out-of-memory bug via the AP4_UrlAtom::AP4_UrlAtom() function. | |||
| CVE-2024-25453 | 0.00 | — | 0.00 | Feb 9, 2024 | Bento4 v1.6.0-640 was discovered to contain a NULL pointer dereference via the AP4_StszAtom::GetSampleSize() function. | |||
| CVE-2023-38666 | 0.00 | — | 0.00 | Aug 22, 2023 | Bento4 v1.6.0-639 was discovered to contain a segmentation violation via the AP4_Processor::ProcessFragments function in mp4encrypt. | |||
| CVE-2023-29575 | 0.00 | — | 0.00 | Apr 21, 2023 | Bento4 v1.6.0-639 was discovered to contain an out-of-memory bug in the mp42aac component. | |||
| CVE-2023-29573 | 0.00 | — | 0.00 | Apr 13, 2023 | Bento4 v1.6.0-639 was discovered to contain an out-of-memory bug in the mp4info component. | |||
| CVE-2023-29574 | 0.00 | — | 0.00 | Apr 12, 2023 | Bento4 v1.6.0-639 was discovered to contain an out-of-memory bug in the mp42avc component. | |||
| CVE-2023-29576 | 0.00 | — | 0.00 | Apr 11, 2023 | Bento4 v1.6.0-639 was discovered to contain a segmentation violation via the AP4_TrunAtom::SetDataOffset(int) function in Ap4TrunAtom.h. | |||
| CVE-2022-4584 | 0.00 | — | 0.01 | Dec 17, 2022 | A vulnerability was found in Axiomatic Bento4 up to 1.6.0-639. It has been rated as critical. Affected by this issue is some unknown functionality of the component mp42aac. The manipulation leads to heap-based buffer overflow. The attack may be launched remotely. The exploit has… | |||
| CVE-2022-3974 | 0.00 | — | 0.01 | Nov 13, 2022 | A vulnerability classified as critical was found in Axiomatic Bento4. Affected by this vulnerability is the function AP4_StdcFileByteStream::ReadPartial of the file Ap4StdCFileByteStream.cpp of the component mp4info. The manipulation leads to heap-based buffer overflow. The… | |||
| CVE-2022-3813 | 0.00 | — | 0.01 | Nov 1, 2022 | A vulnerability classified as problematic has been found in Axiomatic Bento4. This affects an unknown part of the component mp4edit. The manipulation leads to memory leak. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be… | |||
| CVE-2022-3807 | 0.00 | — | 0.01 | Nov 1, 2022 | A vulnerability was found in Axiomatic Bento4. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Incomplete Fix CVE-2019-13238. The manipulation leads to resource consumption. The attack may be launched remotely. The exploit… | |||
| CVE-2022-3817 | 0.00 | — | 0.01 | Nov 1, 2022 | A vulnerability has been found in Axiomatic Bento4 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component mp4mux. The manipulation leads to memory leak. The attack can be launched remotely. The exploit has been disclosed to the… | |||
| CVE-2022-3810 | 0.00 | — | 0.01 | Nov 1, 2022 | A vulnerability was found in Axiomatic Bento4. It has been classified as problematic. This affects the function AP4_File::AP4_File of the file Mp42Hevc.cpp of the component mp42hevc. The manipulation leads to denial of service. It is possible to initiate the attack remotely. The… | |||
| CVE-2022-3816 | 0.00 | — | 0.01 | Nov 1, 2022 | A vulnerability, which was classified as problematic, was found in Axiomatic Bento4. Affected is an unknown function of the component mp4decrypt. The manipulation leads to memory leak. It is possible to launch the attack remotely. The exploit has been disclosed to the public and… | |||
| CVE-2022-3812 | 0.00 | — | 0.01 | Nov 1, 2022 | A vulnerability was found in Axiomatic Bento4. It has been rated as problematic. Affected by this issue is the function AP4_ContainerAtom::AP4_ContainerAtom of the component mp4encrypt. The manipulation leads to memory leak. The attack may be launched remotely. The exploit has… | |||
| CVE-2022-3814 | 0.00 | — | 0.01 | Nov 1, 2022 | A vulnerability classified as problematic was found in Axiomatic Bento4. This vulnerability affects unknown code of the component mp4decrypt. The manipulation leads to memory leak. The attack can be initiated remotely. The exploit has been disclosed to the public and may be… | |||
| CVE-2022-3815 | 0.00 | — | 0.01 | Nov 1, 2022 | A vulnerability, which was classified as problematic, has been found in Axiomatic Bento4. This issue affects some unknown processing of the component mp4decrypt. The manipulation leads to memory leak. The attack may be initiated remotely. The exploit has been disclosed to the… | |||
| CVE-2022-3809 | 0.00 | — | 0.01 | Nov 1, 2022 | A vulnerability was found in Axiomatic Bento4 and classified as problematic. Affected by this issue is the function ParseCommandLine of the file Mp4Tag/Mp4Tag.cpp of the component mp4tag. The manipulation leads to denial of service. The attack may be launched remotely. The… | |||
| CVE-2022-3785 | 0.00 | — | 0.01 | Oct 31, 2022 | A vulnerability, which was classified as critical, has been found in Axiomatic Bento4. Affected by this issue is the function AP4_DataBuffer::SetDataSize of the component Avcinfo. The manipulation leads to heap-based buffer overflow. The attack may be launched remotely. The… | |||
| CVE-2022-3784 | 0.00 | — | 0.01 | Oct 31, 2022 | A vulnerability classified as critical was found in Axiomatic Bento4 5e7bb34. Affected by this vulnerability is the function AP4_Mp4AudioDsiParser::ReadBits of the file Ap4Mp4AudioInfo.cpp of the component mp4hls. The manipulation leads to heap-based buffer overflow. The attack… | |||
| CVE-2022-3664 | 0.00 | — | 0.01 | Oct 26, 2022 | A vulnerability classified as critical has been found in Axiomatic Bento4. Affected is the function AP4_BitStream::WriteBytes of the file Ap4BitStream.cpp of the component avcinfo. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack… | |||
| CVE-2022-3667 | 0.00 | — | 0.01 | Oct 26, 2022 | A vulnerability, which was classified as critical, was found in Axiomatic Bento4. This affects the function AP4_MemoryByteStream::WritePartial of the file Ap4ByteStream.cpp of the component mp42aac. The manipulation leads to heap-based buffer overflow. It is possible to initiate… | |||
| CVE-2022-3665 | 0.00 | — | 0.01 | Oct 26, 2022 | A vulnerability classified as critical was found in Axiomatic Bento4. Affected by this vulnerability is an unknown functionality of the file AvcInfo.cpp of the component avcinfo. The manipulation leads to heap-based buffer overflow. The attack can be launched remotely. The… | |||
| CVE-2022-3666 | 0.00 | — | 0.01 | Oct 26, 2022 | A vulnerability, which was classified as critical, has been found in Axiomatic Bento4. Affected by this issue is the function AP4_LinearReader::Advance of the file Ap4LinearReader.cpp of the component mp42ts. The manipulation leads to use after free. The attack may be launched… | |||
| CVE-2022-3669 | 0.00 | — | 0.01 | Oct 26, 2022 | A vulnerability was found in Axiomatic Bento4 and classified as problematic. This issue affects the function AP4_AvccAtom::Create of the component mp4edit. The manipulation leads to memory leak. The attack may be initiated remotely. The exploit has been disclosed to the public… | |||
| CVE-2022-3662 | 0.00 | — | 0.01 | Oct 26, 2022 | A vulnerability was found in Axiomatic Bento4. It has been declared as critical. This vulnerability affects the function GetOffset of the file Ap4Sample.h of the component mp42hls. The manipulation leads to use after free. The attack can be initiated remotely. The exploit has… | |||
| CVE-2022-3663 | 0.00 | — | 0.01 | Oct 26, 2022 | A vulnerability was found in Axiomatic Bento4. It has been rated as problematic. This issue affects the function AP4_StsdAtom of the file Ap4StsdAtom.cpp of the component MP4fragment. The manipulation leads to null pointer dereference. The attack may be initiated remotely. The… | |||
| CVE-2022-3670 | 0.00 | — | 0.01 | Oct 26, 2022 | A vulnerability was found in Axiomatic Bento4. It has been classified as critical. Affected is the function WriteSample of the component mp42hevc. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed… | |||
| CVE-2022-3668 | 0.00 | — | 0.01 | Oct 26, 2022 | A vulnerability has been found in Axiomatic Bento4 and classified as problematic. This vulnerability affects the function AP4_AtomFactory::CreateAtomFromStream of the component mp4edit. The manipulation leads to memory leak. The attack can be initiated remotely. The exploit has… | |||
| CVE-2022-43035 | 0.00 | — | 0.01 | Oct 19, 2022 | An issue was discovered in Bento4 v1.6.0-639. There is a heap-buffer-overflow in AP4_Dec3Atom::AP4_Dec3Atom at Ap4Dec3Atom.cpp, leading to a Denial of Service (DoS), as demonstrated by mp42aac. | |||
| CVE-2022-40884 | 0.00 | — | 0.00 | Oct 19, 2022 | Bento4 1.6.0 has memory leaks via the mp4fragment. | |||
| CVE-2022-43038 | 0.00 | — | 0.01 | Oct 19, 2022 | Bento4 v1.6.0-639 was discovered to contain a heap overflow via the AP4_BitReader::ReadCache() function in mp42ts. | |||
| CVE-2022-43034 | 0.00 | — | 0.01 | Oct 19, 2022 | An issue was discovered in Bento4 v1.6.0-639. There is a heap buffer overflow vulnerability in the AP4_BitReader::SkipBits(unsigned int) function in mp42ts. | |||
| CVE-2022-43032 | 0.00 | — | 0.01 | Oct 19, 2022 | An issue was discovered in Bento4 v1.6.0-639. There is a memory leak in AP4_DescriptorFactory::CreateDescriptorFromStream in Core/Ap4DescriptorFactory.cpp, as demonstrated by mp42aac. | |||
| CVE-2022-43037 | 0.00 | — | 0.01 | Oct 19, 2022 | An issue was discovered in Bento4 1.6.0-639. There is a memory leak in the function AP4_File::ParseStream in /Core/Ap4File.cpp. | |||
| CVE-2022-43033 | 0.00 | — | 0.01 | Oct 19, 2022 | An issue was discovered in Bento4 1.6.0-639. There is a bad free in the component AP4_HdlrAtom::~AP4_HdlrAtom() which allows attackers to cause a Denial of Service (DoS) via a crafted input. | |||
| CVE-2022-40885 | 0.00 | — | 0.00 | Oct 19, 2022 | Bento4 v1.6.0-639 has a memory allocation issue that can cause denial of service. |
- CVE-2025-25942Feb 19, 2025risk 0.00cvss —epss 0.00
An issue in Bento4 v1.6.0-641 allows an attacker to obtain sensitive information via the the mp4fragment tool when processing invalid files. Specifically, memory allocated in SampleArray::SampleArray in Mp4Fragment.cpp is not properly released.
- CVE-2024-57598Feb 5, 2025risk 0.00cvss —epss 0.00
A floating point exception (divide-by-zero) vulnerability was discovered in Bento4 1.6.0-641 in function AP4_TfraAtom() of Ap4TfraAtom.cpp which allows a remote attacker to cause a denial of service vulnerability.
- CVE-2025-0870Jan 30, 2025risk 0.00cvss —epss 0.01
A vulnerability was found in Axiomatic Bento4 up to 1.6.0-641. It has been rated as critical. Affected by this issue is the function AP4_DataBuffer::GetData in the library Ap4DataBuffer.h. The manipulation leads to heap-based buffer overflow. The attack may be launched remotely.…
- CVE-2025-0753Jan 27, 2025risk 0.00cvss —epss 0.00
A vulnerability classified as critical was found in Axiomatic Bento4 up to 1.6.0. This vulnerability affects the function AP4_StdcFileByteStream::ReadPartial of the component mp42aac. The manipulation leads to heap-based buffer overflow. The attack can be initiated remotely. The…
- CVE-2025-0751Jan 27, 2025risk 0.00cvss —epss 0.00
A vulnerability classified as critical has been found in Axiomatic Bento4 up to 1.6.0. This affects the function AP4_BitReader::ReadBits of the component mp42aac. The manipulation leads to heap-based buffer overflow. It is possible to initiate the attack remotely. The exploit…
- CVE-2024-30808Apr 2, 2024risk 0.00cvss —epss 0.01
An issue was discovered in Bento4 v1.6.0-641-2-g1529b83. There is a heap-use-after-free in AP4_SubStream::~AP4_SubStream at Ap4ByteStream.cpp, leading to a Denial of Service (DoS), as demonstrated by mp42ts.
- CVE-2024-31004Apr 2, 2024risk 0.00cvss —epss 0.01
An issue in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the Ap4StsdAtom.cpp,AP4_StsdAtom::AP4_StsdAtom,mp4fragment.
- CVE-2024-30807Apr 2, 2024risk 0.00cvss —epss 0.01
An issue was discovered in Bento4 v1.6.0-641-2-g1529b83. There is a heap-use-after-free in AP4_UnknownAtom::~AP4_UnknownAtom at Ap4Atom.cpp, leading to a Denial of Service (DoS), as demonstrated by mp42ts.
- CVE-2024-30809Apr 2, 2024risk 0.00cvss —epss 0.01
An issue was discovered in Bento4 v1.6.0-641-2-g1529b83. There is a heap-use-after-free in Ap4Sample.h in AP4_Sample::GetOffset() const, leading to a Denial of Service (DoS), as demonstrated by mp42ts.
- CVE-2024-30806Apr 2, 2024risk 0.00cvss —epss 0.01
An issue was discovered in Bento4 v1.6.0-641-2-g1529b83. There is a heap overflow in AP4_Dec3Atom::AP4_Dec3Atom at Ap4Dec3Atom.cpp, leading to a Denial of Service (DoS), as demonstrated by mp42aac.
- CVE-2024-24155Feb 28, 2024risk 0.00cvss —epss 0.01
Bento4 v1.5.1-628 contains a Memory leak on AP4_Movie::AP4_Movie, parsing tracks and added into m_Tracks list, but mp42aac cannot correctly delete when we got an no audio track found error. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted mp4…
- CVE-2024-25454Feb 9, 2024risk 0.00cvss —epss 0.00
Bento4 v1.6.0-640 was discovered to contain a NULL pointer dereference via the AP4_DescriptorFinder::Test() function.
- CVE-2024-25451Feb 9, 2024risk 0.00cvss —epss 0.01
Bento4 v1.6.0-640 was discovered to contain an out-of-memory bug via the AP4_DataBuffer::ReallocateBuffer() function.
- CVE-2024-25452Feb 9, 2024risk 0.00cvss —epss 0.00
Bento4 v1.6.0-640 was discovered to contain an out-of-memory bug via the AP4_UrlAtom::AP4_UrlAtom() function.
- CVE-2024-25453Feb 9, 2024risk 0.00cvss —epss 0.00
Bento4 v1.6.0-640 was discovered to contain a NULL pointer dereference via the AP4_StszAtom::GetSampleSize() function.
- CVE-2023-38666Aug 22, 2023risk 0.00cvss —epss 0.00
Bento4 v1.6.0-639 was discovered to contain a segmentation violation via the AP4_Processor::ProcessFragments function in mp4encrypt.
- CVE-2023-29575Apr 21, 2023risk 0.00cvss —epss 0.00
Bento4 v1.6.0-639 was discovered to contain an out-of-memory bug in the mp42aac component.
- CVE-2023-29573Apr 13, 2023risk 0.00cvss —epss 0.00
Bento4 v1.6.0-639 was discovered to contain an out-of-memory bug in the mp4info component.
- CVE-2023-29574Apr 12, 2023risk 0.00cvss —epss 0.00
Bento4 v1.6.0-639 was discovered to contain an out-of-memory bug in the mp42avc component.
- CVE-2023-29576Apr 11, 2023risk 0.00cvss —epss 0.00
Bento4 v1.6.0-639 was discovered to contain a segmentation violation via the AP4_TrunAtom::SetDataOffset(int) function in Ap4TrunAtom.h.
- CVE-2022-4584Dec 17, 2022risk 0.00cvss —epss 0.01
A vulnerability was found in Axiomatic Bento4 up to 1.6.0-639. It has been rated as critical. Affected by this issue is some unknown functionality of the component mp42aac. The manipulation leads to heap-based buffer overflow. The attack may be launched remotely. The exploit has…
- CVE-2022-3974Nov 13, 2022risk 0.00cvss —epss 0.01
A vulnerability classified as critical was found in Axiomatic Bento4. Affected by this vulnerability is the function AP4_StdcFileByteStream::ReadPartial of the file Ap4StdCFileByteStream.cpp of the component mp4info. The manipulation leads to heap-based buffer overflow. The…
- CVE-2022-3813Nov 1, 2022risk 0.00cvss —epss 0.01
A vulnerability classified as problematic has been found in Axiomatic Bento4. This affects an unknown part of the component mp4edit. The manipulation leads to memory leak. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be…
- CVE-2022-3807Nov 1, 2022risk 0.00cvss —epss 0.01
A vulnerability was found in Axiomatic Bento4. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Incomplete Fix CVE-2019-13238. The manipulation leads to resource consumption. The attack may be launched remotely. The exploit…
- CVE-2022-3817Nov 1, 2022risk 0.00cvss —epss 0.01
A vulnerability has been found in Axiomatic Bento4 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component mp4mux. The manipulation leads to memory leak. The attack can be launched remotely. The exploit has been disclosed to the…
- CVE-2022-3810Nov 1, 2022risk 0.00cvss —epss 0.01
A vulnerability was found in Axiomatic Bento4. It has been classified as problematic. This affects the function AP4_File::AP4_File of the file Mp42Hevc.cpp of the component mp42hevc. The manipulation leads to denial of service. It is possible to initiate the attack remotely. The…
- CVE-2022-3816Nov 1, 2022risk 0.00cvss —epss 0.01
A vulnerability, which was classified as problematic, was found in Axiomatic Bento4. Affected is an unknown function of the component mp4decrypt. The manipulation leads to memory leak. It is possible to launch the attack remotely. The exploit has been disclosed to the public and…
- CVE-2022-3812Nov 1, 2022risk 0.00cvss —epss 0.01
A vulnerability was found in Axiomatic Bento4. It has been rated as problematic. Affected by this issue is the function AP4_ContainerAtom::AP4_ContainerAtom of the component mp4encrypt. The manipulation leads to memory leak. The attack may be launched remotely. The exploit has…
- CVE-2022-3814Nov 1, 2022risk 0.00cvss —epss 0.01
A vulnerability classified as problematic was found in Axiomatic Bento4. This vulnerability affects unknown code of the component mp4decrypt. The manipulation leads to memory leak. The attack can be initiated remotely. The exploit has been disclosed to the public and may be…
- CVE-2022-3815Nov 1, 2022risk 0.00cvss —epss 0.01
A vulnerability, which was classified as problematic, has been found in Axiomatic Bento4. This issue affects some unknown processing of the component mp4decrypt. The manipulation leads to memory leak. The attack may be initiated remotely. The exploit has been disclosed to the…
- CVE-2022-3809Nov 1, 2022risk 0.00cvss —epss 0.01
A vulnerability was found in Axiomatic Bento4 and classified as problematic. Affected by this issue is the function ParseCommandLine of the file Mp4Tag/Mp4Tag.cpp of the component mp4tag. The manipulation leads to denial of service. The attack may be launched remotely. The…
- CVE-2022-3785Oct 31, 2022risk 0.00cvss —epss 0.01
A vulnerability, which was classified as critical, has been found in Axiomatic Bento4. Affected by this issue is the function AP4_DataBuffer::SetDataSize of the component Avcinfo. The manipulation leads to heap-based buffer overflow. The attack may be launched remotely. The…
- CVE-2022-3784Oct 31, 2022risk 0.00cvss —epss 0.01
A vulnerability classified as critical was found in Axiomatic Bento4 5e7bb34. Affected by this vulnerability is the function AP4_Mp4AudioDsiParser::ReadBits of the file Ap4Mp4AudioInfo.cpp of the component mp4hls. The manipulation leads to heap-based buffer overflow. The attack…
- CVE-2022-3664Oct 26, 2022risk 0.00cvss —epss 0.01
A vulnerability classified as critical has been found in Axiomatic Bento4. Affected is the function AP4_BitStream::WriteBytes of the file Ap4BitStream.cpp of the component avcinfo. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack…
- CVE-2022-3667Oct 26, 2022risk 0.00cvss —epss 0.01
A vulnerability, which was classified as critical, was found in Axiomatic Bento4. This affects the function AP4_MemoryByteStream::WritePartial of the file Ap4ByteStream.cpp of the component mp42aac. The manipulation leads to heap-based buffer overflow. It is possible to initiate…
- CVE-2022-3665Oct 26, 2022risk 0.00cvss —epss 0.01
A vulnerability classified as critical was found in Axiomatic Bento4. Affected by this vulnerability is an unknown functionality of the file AvcInfo.cpp of the component avcinfo. The manipulation leads to heap-based buffer overflow. The attack can be launched remotely. The…
- CVE-2022-3666Oct 26, 2022risk 0.00cvss —epss 0.01
A vulnerability, which was classified as critical, has been found in Axiomatic Bento4. Affected by this issue is the function AP4_LinearReader::Advance of the file Ap4LinearReader.cpp of the component mp42ts. The manipulation leads to use after free. The attack may be launched…
- CVE-2022-3669Oct 26, 2022risk 0.00cvss —epss 0.01
A vulnerability was found in Axiomatic Bento4 and classified as problematic. This issue affects the function AP4_AvccAtom::Create of the component mp4edit. The manipulation leads to memory leak. The attack may be initiated remotely. The exploit has been disclosed to the public…
- CVE-2022-3662Oct 26, 2022risk 0.00cvss —epss 0.01
A vulnerability was found in Axiomatic Bento4. It has been declared as critical. This vulnerability affects the function GetOffset of the file Ap4Sample.h of the component mp42hls. The manipulation leads to use after free. The attack can be initiated remotely. The exploit has…
- CVE-2022-3663Oct 26, 2022risk 0.00cvss —epss 0.01
A vulnerability was found in Axiomatic Bento4. It has been rated as problematic. This issue affects the function AP4_StsdAtom of the file Ap4StsdAtom.cpp of the component MP4fragment. The manipulation leads to null pointer dereference. The attack may be initiated remotely. The…
- CVE-2022-3670Oct 26, 2022risk 0.00cvss —epss 0.01
A vulnerability was found in Axiomatic Bento4. It has been classified as critical. Affected is the function WriteSample of the component mp42hevc. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed…
- CVE-2022-3668Oct 26, 2022risk 0.00cvss —epss 0.01
A vulnerability has been found in Axiomatic Bento4 and classified as problematic. This vulnerability affects the function AP4_AtomFactory::CreateAtomFromStream of the component mp4edit. The manipulation leads to memory leak. The attack can be initiated remotely. The exploit has…
- CVE-2022-43035Oct 19, 2022risk 0.00cvss —epss 0.01
An issue was discovered in Bento4 v1.6.0-639. There is a heap-buffer-overflow in AP4_Dec3Atom::AP4_Dec3Atom at Ap4Dec3Atom.cpp, leading to a Denial of Service (DoS), as demonstrated by mp42aac.
- CVE-2022-40884Oct 19, 2022risk 0.00cvss —epss 0.00
Bento4 1.6.0 has memory leaks via the mp4fragment.
- CVE-2022-43038Oct 19, 2022risk 0.00cvss —epss 0.01
Bento4 v1.6.0-639 was discovered to contain a heap overflow via the AP4_BitReader::ReadCache() function in mp42ts.
- CVE-2022-43034Oct 19, 2022risk 0.00cvss —epss 0.01
An issue was discovered in Bento4 v1.6.0-639. There is a heap buffer overflow vulnerability in the AP4_BitReader::SkipBits(unsigned int) function in mp42ts.
- CVE-2022-43032Oct 19, 2022risk 0.00cvss —epss 0.01
An issue was discovered in Bento4 v1.6.0-639. There is a memory leak in AP4_DescriptorFactory::CreateDescriptorFromStream in Core/Ap4DescriptorFactory.cpp, as demonstrated by mp42aac.
- CVE-2022-43037Oct 19, 2022risk 0.00cvss —epss 0.01
An issue was discovered in Bento4 1.6.0-639. There is a memory leak in the function AP4_File::ParseStream in /Core/Ap4File.cpp.
- CVE-2022-43033Oct 19, 2022risk 0.00cvss —epss 0.01
An issue was discovered in Bento4 1.6.0-639. There is a bad free in the component AP4_HdlrAtom::~AP4_HdlrAtom() which allows attackers to cause a Denial of Service (DoS) via a crafted input.
- CVE-2022-40885Oct 19, 2022risk 0.00cvss —epss 0.00
Bento4 v1.6.0-639 has a memory allocation issue that can cause denial of service.
Page 2 of 4