Lucene search

K

Bento4 Security Vulnerabilities

cve
cve

CVE-2024-25453

Bento4 v1.6.0-640 was discovered to contain a NULL pointer dereference via the AP4_StszAtom::GetSampleSize()...

5.5CVSS

5.5AI Score

0.0004EPSS

2024-02-09 03:15 PM
15
cve
cve

CVE-2024-25454

Bento4 v1.6.0-640 was discovered to contain a NULL pointer dereference via the AP4_DescriptorFinder::Test()...

5.5CVSS

5.5AI Score

0.0004EPSS

2024-02-09 03:15 PM
30
cve
cve

CVE-2024-25451

Bento4 v1.6.0-640 was discovered to contain an out-of-memory bug via the AP4_DataBuffer::ReallocateBuffer()...

6.5CVSS

6.5AI Score

0.0005EPSS

2024-02-09 03:15 PM
38
cve
cve

CVE-2024-25452

Bento4 v1.6.0-640 was discovered to contain an out-of-memory bug via the AP4_UrlAtom::AP4_UrlAtom()...

5.5CVSS

5.5AI Score

0.0004EPSS

2024-02-09 03:15 PM
33
cve
cve

CVE-2023-38666

Bento4 v1.6.0-639 was discovered to contain a segmentation violation via the AP4_Processor::ProcessFragments function in...

5.5CVSS

5.5AI Score

0.0004EPSS

2023-08-22 07:16 PM
13
cve
cve

CVE-2023-29575

Bento4 v1.6.0-639 was discovered to contain an out-of-memory bug in the mp42aac...

5.5CVSS

5.5AI Score

0.001EPSS

2023-04-21 02:15 PM
16
cve
cve

CVE-2023-29573

Bento4 v1.6.0-639 was discovered to contain an out-of-memory bug in the mp4info...

5.5CVSS

5.5AI Score

0.001EPSS

2023-04-13 08:15 PM
15
cve
cve

CVE-2023-29574

Bento4 v1.6.0-639 was discovered to contain an out-of-memory bug in the mp42avc...

5.5CVSS

5.5AI Score

0.001EPSS

2023-04-12 01:15 PM
76
cve
cve

CVE-2023-29576

Bento4 v1.6.0-639 was discovered to contain a segmentation violation via the AP4_TrunAtom::SetDataOffset(int) function in...

5.5CVSS

5.5AI Score

0.001EPSS

2023-04-11 09:15 PM
11
cve
cve

CVE-2022-4584

A vulnerability was found in Axiomatic Bento4 up to 1.6.0-639. It has been rated as critical. Affected by this issue is some unknown functionality of the component mp42aac. The manipulation leads to heap-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to.....

8.8CVSS

8.8AI Score

0.002EPSS

2022-12-17 01:15 PM
39
cve
cve

CVE-2022-3974

A vulnerability classified as critical was found in Axiomatic Bento4. Affected by this vulnerability is the function AP4_StdcFileByteStream::ReadPartial of the file Ap4StdCFileByteStream.cpp of the component mp4info. The manipulation leads to heap-based buffer overflow. The attack can be launched.....

8.8CVSS

8.9AI Score

0.002EPSS

2022-11-13 10:15 AM
32
18
cve
cve

CVE-2022-3809

A vulnerability was found in Axiomatic Bento4 and classified as problematic. Affected by this issue is the function ParseCommandLine of the file Mp4Tag/Mp4Tag.cpp of the component mp4tag. The manipulation leads to denial of service. The attack may be launched remotely. The exploit has been...

6.5CVSS

6.4AI Score

0.001EPSS

2022-11-02 01:15 PM
24
cve
cve

CVE-2022-3810

A vulnerability was found in Axiomatic Bento4. It has been classified as problematic. This affects the function AP4_File::AP4_File of the file Mp42Hevc.cpp of the component mp42hevc. The manipulation leads to denial of service. It is possible to initiate the attack remotely. The exploit has been...

6.5CVSS

6.4AI Score

0.001EPSS

2022-11-02 01:15 PM
16
cve
cve

CVE-2022-3812

A vulnerability was found in Axiomatic Bento4. It has been rated as problematic. Affected by this issue is the function AP4_ContainerAtom::AP4_ContainerAtom of the component mp4encrypt. The manipulation leads to memory leak. The attack may be launched remotely. The exploit has been disclosed to...

6.5CVSS

6.4AI Score

0.001EPSS

2022-11-01 10:15 PM
25
4
cve
cve

CVE-2022-3816

A vulnerability, which was classified as problematic, was found in Axiomatic Bento4. Affected is an unknown function of the component mp4decrypt. The manipulation leads to memory leak. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used....

6.5CVSS

6.5AI Score

0.001EPSS

2022-11-01 10:15 PM
25
6
cve
cve

CVE-2022-3817

A vulnerability has been found in Axiomatic Bento4 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component mp4mux. The manipulation leads to memory leak. The attack can be launched remotely. The exploit has been disclosed to the public and may be.....

6.5CVSS

6.5AI Score

0.001EPSS

2022-11-01 10:15 PM
28
6
cve
cve

CVE-2022-3814

A vulnerability classified as problematic was found in Axiomatic Bento4. This vulnerability affects unknown code of the component mp4decrypt. The manipulation leads to memory leak. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of....

6.5CVSS

6.6AI Score

0.001EPSS

2022-11-01 10:15 PM
22
4
cve
cve

CVE-2022-3813

A vulnerability classified as problematic has been found in Axiomatic Bento4. This affects an unknown part of the component mp4edit. The manipulation leads to memory leak. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated...

6.5CVSS

6.5AI Score

0.001EPSS

2022-11-01 10:15 PM
20
4
cve
cve

CVE-2022-3815

A vulnerability, which was classified as problematic, has been found in Axiomatic Bento4. This issue affects some unknown processing of the component mp4decrypt. The manipulation leads to memory leak. The attack may be initiated remotely. The exploit has been disclosed to the public and may be...

6.5CVSS

6.5AI Score

0.001EPSS

2022-11-01 10:15 PM
18
4
cve
cve

CVE-2022-3807

A vulnerability was found in Axiomatic Bento4. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Incomplete Fix CVE-2019-13238. The manipulation leads to resource consumption. The attack may be launched remotely. The exploit has been disclosed.....

6.5CVSS

6.8AI Score

0.002EPSS

2022-11-01 08:15 PM
20
2
cve
cve

CVE-2022-3784

A vulnerability classified as critical was found in Axiomatic Bento4 5e7bb34. Affected by this vulnerability is the function AP4_Mp4AudioDsiParser::ReadBits of the file Ap4Mp4AudioInfo.cpp of the component mp4hls. The manipulation leads to heap-based buffer overflow. The attack can be launched...

7.8CVSS

7.8AI Score

0.001EPSS

2022-10-31 09:15 PM
24
2
cve
cve

CVE-2022-3785

A vulnerability, which was classified as critical, has been found in Axiomatic Bento4. Affected by this issue is the function AP4_DataBuffer::SetDataSize of the component Avcinfo. The manipulation leads to heap-based buffer overflow. The attack may be launched remotely. The exploit has been...

7.8CVSS

7.7AI Score

0.001EPSS

2022-10-31 09:15 PM
31
cve
cve

CVE-2022-3670

A vulnerability was found in Axiomatic Bento4. It has been classified as critical. Affected is the function WriteSample of the component mp42hevc. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and...

7.8CVSS

7.8AI Score

0.001EPSS

2022-10-26 07:15 PM
35
6
cve
cve

CVE-2022-3669

A vulnerability was found in Axiomatic Bento4 and classified as problematic. This issue affects the function AP4_AvccAtom::Create of the component mp4edit. The manipulation leads to memory leak. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The....

5.5CVSS

5.5AI Score

0.001EPSS

2022-10-26 07:15 PM
30
6
cve
cve

CVE-2022-3668

A vulnerability has been found in Axiomatic Bento4 and classified as problematic. This vulnerability affects the function AP4_AtomFactory::CreateAtomFromStream of the component mp4edit. The manipulation leads to memory leak. The attack can be initiated remotely. The exploit has been disclosed to...

5.5CVSS

5.5AI Score

0.001EPSS

2022-10-26 07:15 PM
37
6
cve
cve

CVE-2022-3667

A vulnerability, which was classified as critical, was found in Axiomatic Bento4. This affects the function AP4_MemoryByteStream::WritePartial of the file Ap4ByteStream.cpp of the component mp42aac. The manipulation leads to heap-based buffer overflow. It is possible to initiate the attack...

7.5CVSS

7.7AI Score

0.001EPSS

2022-10-26 07:15 PM
40
8
cve
cve

CVE-2022-3666

A vulnerability, which was classified as critical, has been found in Axiomatic Bento4. Affected by this issue is the function AP4_LinearReader::Advance of the file Ap4LinearReader.cpp of the component mp42ts. The manipulation leads to use after free. The attack may be launched remotely. The...

7.8CVSS

7.6AI Score

0.001EPSS

2022-10-26 07:15 PM
33
6
cve
cve

CVE-2022-3665

A vulnerability classified as critical was found in Axiomatic Bento4. Affected by this vulnerability is an unknown functionality of the file AvcInfo.cpp of the component avcinfo. The manipulation leads to heap-based buffer overflow. The attack can be launched remotely. The exploit has been...

7.8CVSS

7.8AI Score

0.001EPSS

2022-10-26 07:15 PM
25
8
cve
cve

CVE-2022-3664

A vulnerability classified as critical has been found in Axiomatic Bento4. Affected is the function AP4_BitStream::WriteBytes of the file Ap4BitStream.cpp of the component avcinfo. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack remotely. The exploit has...

7.8CVSS

7.8AI Score

0.001EPSS

2022-10-26 07:15 PM
37
6
cve
cve

CVE-2022-3663

A vulnerability was found in Axiomatic Bento4. It has been rated as problematic. This issue affects the function AP4_StsdAtom of the file Ap4StsdAtom.cpp of the component MP4fragment. The manipulation leads to null pointer dereference. The attack may be initiated remotely. The exploit has been...

5.5CVSS

5.5AI Score

0.001EPSS

2022-10-26 07:15 PM
36
2
cve
cve

CVE-2022-3662

A vulnerability was found in Axiomatic Bento4. It has been declared as critical. This vulnerability affects the function GetOffset of the file Ap4Sample.h of the component mp42hls. The manipulation leads to use after free. The attack can be initiated remotely. The exploit has been disclosed to the....

7.8CVSS

7.6AI Score

0.001EPSS

2022-10-26 07:15 PM
33
4
cve
cve

CVE-2022-40885

Bento4 v1.6.0-639 has a memory allocation issue that can cause denial of...

5.5CVSS

5.4AI Score

0.001EPSS

2022-10-19 06:15 PM
22
cve
cve

CVE-2022-40884

Bento4 1.6.0 has memory leaks via the...

5.5CVSS

5.5AI Score

0.001EPSS

2022-10-19 06:15 PM
18
cve
cve

CVE-2022-43038

Bento4 v1.6.0-639 was discovered to contain a heap overflow via the AP4_BitReader::ReadCache() function in...

6.5CVSS

6.6AI Score

0.001EPSS

2022-10-19 02:15 PM
23
4
cve
cve

CVE-2022-43037

An issue was discovered in Bento4 1.6.0-639. There is a memory leak in the function AP4_File::ParseStream in...

6.5CVSS

6.4AI Score

0.001EPSS

2022-10-19 02:15 PM
23
4
cve
cve

CVE-2022-43032

An issue was discovered in Bento4 v1.6.0-639. There is a memory leak in AP4_DescriptorFactory::CreateDescriptorFromStream in Core/Ap4DescriptorFactory.cpp, as demonstrated by...

6.5CVSS

6.4AI Score

0.001EPSS

2022-10-19 02:15 PM
25
4
cve
cve

CVE-2022-43034

An issue was discovered in Bento4 v1.6.0-639. There is a heap buffer overflow vulnerability in the AP4_BitReader::SkipBits(unsigned int) function in...

6.5CVSS

6.7AI Score

0.001EPSS

2022-10-19 02:15 PM
16
6
cve
cve

CVE-2022-43033

An issue was discovered in Bento4 1.6.0-639. There is a bad free in the component AP4_HdlrAtom::~AP4_HdlrAtom() which allows attackers to cause a Denial of Service (DoS) via a crafted...

6.5CVSS

6.3AI Score

0.001EPSS

2022-10-19 02:15 PM
23
4
cve
cve

CVE-2022-43035

An issue was discovered in Bento4 v1.6.0-639. There is a heap-buffer-overflow in AP4_Dec3Atom::AP4_Dec3Atom at Ap4Dec3Atom.cpp, leading to a Denial of Service (DoS), as demonstrated by...

6.5CVSS

6.3AI Score

0.001EPSS

2022-10-19 02:15 PM
19
6
cve
cve

CVE-2018-20502

An issue was discovered in Bento4 1.5.1-627. There is an attempt at excessive memory allocation in the AP4_DataBuffer class when called from AP4_HvccAtom::Create in...

6.5CVSS

6.4AI Score

0.001EPSS

2022-10-03 04:22 PM
19
cve
cve

CVE-2018-20409

An issue was discovered in Bento4 1.5.1-627. There is a heap-based buffer over-read in AP4_AvccAtom::Create in Core/Ap4AvccAtom.cpp, as demonstrated by...

6.5CVSS

6.5AI Score

0.001EPSS

2022-10-03 04:22 PM
17
cve
cve

CVE-2018-20408

An issue was discovered in Bento4 1.5.1-627. There is a memory leak in AP4_StdcFileByteStream::Create in System/StdC/Ap4StdCFileByteStream.cpp, as demonstrated by...

6.5CVSS

6.4AI Score

0.001EPSS

2022-10-03 04:22 PM
18
cve
cve

CVE-2018-20095

An issue was discovered in EnsureCapacity in Core/Ap4Array.h in Bento4 1.5.1-627. Crafted MP4 input triggers an attempt at excessive memory allocation, as demonstrated by...

6.5CVSS

6.3AI Score

0.001EPSS

2022-10-03 04:22 PM
16
cve
cve

CVE-2018-20407

An issue was discovered in Bento4 1.5.1-627. There is a memory leak in AP4_DescriptorFactory::CreateDescriptorFromStream in Core/Ap4DescriptorFactory.cpp, as demonstrated by...

6.5CVSS

6.4AI Score

0.001EPSS

2022-10-03 04:22 PM
17
cve
cve

CVE-2018-5253

The AP4_FtypAtom class in Core/Ap4FtypAtom.cpp in Bento4 1.5.1.0 has an Infinite loop via a crafted MP4 file that triggers size...

7.8CVSS

7.4AI Score

0.001EPSS

2022-10-03 04:22 PM
18
cve
cve

CVE-2019-6132

An issue was discovered in Bento4 v1.5.1-627. There is a memory leak in AP4_DescriptorFactory::CreateDescriptorFromStream in Core/Ap4DescriptorFactory.cpp when called from the AP4_EsdsAtom class in Core/Ap4EsdsAtom.cpp, as demonstrated by...

7.5CVSS

7.4AI Score

0.001EPSS

2022-10-03 04:19 PM
19
cve
cve

CVE-2022-41429

Bento4 v1.6.0-639 was discovered to contain a heap overflow via the AP4_Atom::TypeFromString function in...

8.8CVSS

8.8AI Score

0.002EPSS

2022-10-03 02:15 PM
28
6
cve
cve

CVE-2022-41430

Bento4 v1.6.0-639 was discovered to contain a heap overflow via the AP4_BitReader::ReadBit function in...

8.8CVSS

8.8AI Score

0.002EPSS

2022-10-03 02:15 PM
25
6
cve
cve

CVE-2022-41427

Bento4 v1.6.0-639 was discovered to contain a memory leak in the AP4_AvcFrameParser::Feed function in...

6.5CVSS

6.4AI Score

0.001EPSS

2022-10-03 02:15 PM
29
4
cve
cve

CVE-2022-41428

Bento4 v1.6.0-639 was discovered to contain a heap overflow via the AP4_BitReader::ReadBits function in...

8.8CVSS

8.8AI Score

0.002EPSS

2022-10-03 02:15 PM
31
4
Total number of security vulnerabilities151