VendorsAxiosysbento4all versions
Vulnerabilities

Axiosys Axiomatic Systems Bento4

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

156CVEs
CVE-2018-13846
An issue has been found in Bento4 1.5.1-624. AP4_Mpeg2TsVideoSampleStream::WriteSample in Core/Ap4Mpeg2Ts.cpp has a heap-based buffer over-read after a call from Mp42Ts.cpp, a related issue to CVE-2018-14532.
Published 2018-07-10 · Modified
9.8EPSS 0.017
CVE-2018-14532
An issue was discovered in Bento4 1.5.1-624. There is a heap-based buffer over-read in AP4_Mpeg2TsVideoSampleStream::WriteSample in Core/Ap4Mpeg2Ts.cpp after a call from Mp42Hls.cpp, a related issue to CVE-2018-13846.
Published 2018-07-23 · Modified
9.8EPSS 0.017
CVE-2018-14531
An issue was discovered in Bento4 1.5.1-624. There is an unspecified "heap-buffer-overflow" crash in the AP4_HvccAtom class in Core/Ap4HvccAtom.cpp.
Published 2018-07-23 · Modified
9.8EPSS 0.016
CVE-2024-31004
An issue in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the Ap4StsdAtom.cpp,AP4_StsdAtom::AP4_StsdAtom,mp4fragment.
Published 2024-04-02 · Modified
9.8EPSS 0.015
CVE-2024-31002
Buffer Overflow vulnerability in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the AP4 BitReader::ReadCache() at Ap4Utils.cpp component.
Published 2024-04-02 · Analyzed
9.8EPSS 0.014
CVE-2019-8380
An issue was discovered in Bento4 1.5.1-628. A NULL pointer dereference occurs in AP4_Track::GetSampleIndexForTimeStampMs() located in Core/Ap4Track.cpp. It can triggered by sending a crafted file to the mp4audioclip binary. It allows an attacker to cause a Denial of Service (Segmentation fault) or possibly have unspecified other impact.
Published 2019-02-17 · Modified
8.8EPSS 0.016
CVE-2019-8382
An issue was discovered in Bento4 1.5.1-628. A NULL pointer dereference occurs in the function AP4_List:Find located in Core/Ap4List.h when called from Core/Ap4Movie.cpp. It can be triggered by sending a crafted file to the mp4dump binary. It allows an attacker to cause a Denial of Service (Segmentation fault) or possibly have unspecified other impact.
Published 2019-02-17 · Modified
8.8EPSS 0.016
CVE-2018-14584
An issue has been discovered in Bento4 1.5.1-624. AP4_AvccAtom::Create in Core/Ap4AvccAtom.cpp has a heap-based buffer over-read.
Published 2018-07-24 · Modified
8.8EPSS 0.016
CVE-2019-9544
An issue was discovered in Bento4 1.5.1-628. An out of bounds write occurs in AP4_CttsTableEntry::AP4_CttsTableEntry() located in Core/Ap4Array.h. It can be triggered by sending a crafted file to (for example) the mp42hls binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact.
Published 2019-03-01 · Modified
8.8EPSS 0.016
CVE-2019-8378
An issue was discovered in Bento4 1.5.1-628. A heap-based buffer over-read exists in AP4_BitStream::ReadBytes() in Codecs/Ap4BitStream.cpp, a similar issue to CVE-2017-14645. It can be triggered by sending a crafted file to the aac2mp4 binary. It allows an attacker to cause a Denial of Service (Segmentation fault) or possibly have unspecified other impact.
Published 2019-02-17 · Modified
8.8EPSS 0.016
CVE-2021-32265
An issue was discovered in Bento4 through v1.6.0-637. A global-buffer-overflow exists in the function AP4_MemoryByteStream::WritePartial() located in Ap4ByteStream.cpp. It allows an attacker to cause code execution or information disclosure.
Published 2021-09-20 · Modified
8.8EPSS 0.016
CVE-2024-31003
Buffer Overflow vulnerability in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the AP4_MemoryByteStream::WritePartial at Ap4ByteStream.cpp.
Published 2024-04-02 · Analyzed
8.8EPSS 0.015
CVE-2018-14587
An issue has been discovered in Bento4 1.5.1-624. AP4_MemoryByteStream::WritePartial in Core/Ap4ByteStream.cpp has a buffer over-read.
Published 2018-07-24 · Modified
8.8EPSS 0.015
CVE-2019-15049
An issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer over-read in the AP4_Dec3Atom class at Core/Ap4Dec3Atom.cpp.
Published 2019-08-14 · Modified
8.8EPSS 0.015
CVE-2018-14586
An issue has been discovered in Bento4 1.5.1-624. A SEGV can occur in AP4_Mpeg2TsAudioSampleStream::WriteSample in Core/Ap4Mpeg2Ts.cpp, a different vulnerability than CVE-2018-14532.
Published 2018-07-24 · Modified
8.8EPSS 0.015
CVE-2018-14585
An issue has been discovered in Bento4 1.5.1-624. AP4_BytesToUInt16BE in Core/Ap4Utils.h has a heap-based buffer over-read after a call from the AP4_Stz2Atom class.
Published 2018-07-24 · Modified
8.8EPSS 0.015
CVE-2018-14589
An issue has been discovered in Bento4 1.5.1-624. AP4_Mp4AudioDsiParser::ReadBits in Codecs/Ap4Mp4AudioInfo.cpp has a heap-based buffer over-read.
Published 2018-07-24 · Modified
8.8EPSS 0.015
CVE-2019-15050
An issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer over-read in the AP4_AvccAtom class at Core/Ap4AvccAtom.cpp.
Published 2019-08-14 · Modified
8.8EPSS 0.015
CVE-2019-15047
An issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer over-read in the function AP4_BitReader::SkipBits at Core/Ap4Utils.cpp.
Published 2019-08-14 · Modified
8.8EPSS 0.015
CVE-2019-15048
An issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer overflow in the AP4_RtpAtom class at Core/Ap4RtpAtom.cpp.
Published 2019-08-14 · Modified
8.8EPSS 0.014
CVE-2022-4584
Axiomatic Bento4 mp42aac heap-based overflow
Published 2022-12-17 · Modified
8.8EPSS 0.010
CVE-2022-3974
Axiomatic Bento4 mp4info Ap4StdCFileByteStream.cpp ReadPartial heap-based overflow
Published 2022-11-13 · Modified
8.8EPSS 0.008
CVE-2022-41428
Bento4 v1.6.0-639 was discovered to contain a heap overflow via the AP4_BitReader::ReadBits function in mp4mux.
Published 2022-10-03 · Modified
8.8EPSS 0.008
CVE-2022-41429
Bento4 v1.6.0-639 was discovered to contain a heap overflow via the AP4_Atom::TypeFromString function in mp4tag.
Published 2022-10-03 · Modified
8.8EPSS 0.008
CVE-2022-41430
Bento4 v1.6.0-639 was discovered to contain a heap overflow via the AP4_BitReader::ReadBit function in mp4mux.
Published 2022-10-03 · Modified
8.8EPSS 0.008
CVE-2024-31005
An issue in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the Ap4MdhdAtom.cpp,AP4_MdhdAtom::AP4_MdhdAtom,mp4fragment
Published 2024-04-02 · Analyzed
8.1EPSS 0.012
CVE-2022-27607
Bento4 1.6.0-639 has a heap-based buffer over-read in the AP4_HvccAtom class, a different issue than CVE-2018-14531.
Published 2022-03-21 · Modified
8.1EPSS 0.010
CVE-2017-14260
In the SDK in Bento4 1.5.0-616, the AP4_StssAtom class in Ap4StssAtom.cpp contains a Write Memory Access Violation vulnerability. It is possible to exploit this vulnerability and possibly execute arbitrary code by opening a crafted .MP4 file.
Published 2017-09-11 · Modified
7.8EPSS 0.014
CVE-2018-5253
The AP4_FtypAtom class in Core/Ap4FtypAtom.cpp in Bento4 1.5.1.0 has an Infinite loop via a crafted MP4 file that triggers size mishandling.
Published 2018-01-05 · Modified
7.8EPSS 0.010
CVE-2019-20090
An issue was discovered in Bento4 1.5.1.0. There is a use-after-free in AP4_Sample::GetOffset in Core/Ap4Sample.h when called from Ap4LinearReader.cpp.
Published 2019-12-30 · Modified
7.8EPSS 0.008
CVE-2022-3670
Axiomatic Bento4 mp42hevc WriteSample heap-based overflow
Published 2022-10-26 · Modified
7.8EPSS 0.007
CVE-2022-3665
Axiomatic Bento4 avcinfo AvcInfo.cpp heap-based overflow
Published 2022-10-26 · Modified
7.8EPSS 0.007
CVE-2022-3664
Axiomatic Bento4 avcinfo Ap4BitStream.cpp WriteBytes heap-based overflow
Published 2022-10-26 · Modified
7.8EPSS 0.007
CVE-2022-3785
Axiomatic Bento4 Avcinfo SetDataSize heap-based overflow
Published 2022-10-31 · Modified
7.8EPSS 0.007
CVE-2022-3666
Axiomatic Bento4 mp42ts Ap4LinearReader.cpp Advance use after free
Published 2022-10-26 · Modified
7.8EPSS 0.007
CVE-2022-3662
Axiomatic Bento4 mp42hls Ap4Sample.h GetOffset use after free
Published 2022-10-26 · Modified
7.8EPSS 0.007
CVE-2022-3784
Axiomatic Bento4 mp4hls Ap4Mp4AudioInfo.cpp ReadBits heap-based overflow
Published 2022-10-31 · Modified
7.8EPSS 0.006
CVE-2019-17529
An issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer over-read in AP4_CencSampleEncryption::DoInspectFields in Core/Ap4CommonEncryption.cpp when called from AP4_Atom::Inspect in Core/Ap4Atom.cpp.
Published 2019-10-12 · Modified
7.8EPSS 0.005
CVE-2019-17530
An issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer over-read in AP4_PrintInspector::AddField in Core/Ap4Atom.cpp when called from AP4_CencSampleEncryption::DoInspectFields in Core/Ap4CommonEncryption.cpp, when called from AP4_Atom::Inspect in Core/Ap4Atom.cpp.
Published 2019-10-12 · Modified
7.8EPSS 0.005
CVE-2025-25943
Buffer Overflow vulnerability in Bento4 v.1.6.0-641 allows a local attacker to execute arbitrary code via the AP4_Stz2Atom::AP4_Stz2Atom component located in Ap4Stz2Atom.cpp.
Published 2025-02-19 · Analyzed
7.8EPSS 0.002
1 / 4Next →