VendorsAxiosysbento4all versions
Vulnerabilities

Axiosys Axiomatic Systems Bento4

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

156CVEs
CVE-2017-12475
The AP4_Processor::Process function in Core/Ap4Processor.cpp in Bento4 mp4encrypt before 1.5.0-616 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted mp4 file.
Published 2017-09-06 · Modified
5.5EPSS 0.012
CVE-2019-16349
Bento4 1.5.1-628 has a NULL pointer dereference in AP4_ByteStream::ReadUI32 in Core/Ap4ByteStream.cpp when called from the AP4_TrunAtom class.
Published 2019-09-16 · Modified
5.5EPSS 0.009
CVE-2018-14543
There exists one NULL pointer dereference vulnerability in AP4_JsonInspector::AddField in Ap4Atom.cpp in Bento4 1.5.1-624, which can allow attackers to cause a denial-of-service via a crafted mp4 file. This vulnerability can be triggered by the executable mp4dump.
Published 2018-07-23 · Modified
5.5EPSS 0.008
CVE-2018-14544
There exists one invalid memory read bug in AP4_SampleDescription::GetFormat() in Ap4SampleDescription.h in Bento4 1.5.1-624, which can allow attackers to cause a denial-of-service via a crafted mp4 file. This vulnerability can be triggered by the executable mp42ts.
Published 2018-07-23 · Modified
5.5EPSS 0.008
CVE-2018-14545
There exists one invalid memory read bug in AP4_SampleDescription::GetType() in Ap4SampleDescription.h in Bento4 1.5.1-624, which can allow attackers to cause a denial-of-service via a crafted mp4 file. This vulnerability can be triggered by the executable mp42ts.
Published 2018-07-23 · Modified
5.5EPSS 0.008
CVE-2019-20091
An issue was discovered in Bento4 1.5.1.0. There is a NULL pointer dereference in AP4_Descriptor::GetTag in mp42ts when called from AP4_DecoderConfigDescriptor::GetDecoderSpecificInfoDescriptor in Ap4DecoderConfigDescriptor.cpp.
Published 2019-12-30 · Modified
5.5EPSS 0.008
CVE-2019-20092
An issue was discovered in Bento4 1.5.1.0. There is a NULL pointer dereference in AP4_Descriptor::GetTag in mp42ts when called from AP4_EsDescriptor::GetDecoderConfigDescriptor in Ap4EsDescriptor.cpp.
Published 2019-12-30 · Modified
5.5EPSS 0.008
CVE-2020-23912
An issue was discovered in Bento4 through v1.6.0-637. A NULL pointer dereference exists in the function AP4_StszAtom::GetSampleSize() located in Ap4StszAtom.cpp. It allows an attacker to cause Denial of Service.
Published 2021-04-21 · Modified
5.5EPSS 0.007
CVE-2022-3669
Axiomatic Bento4 mp4edit Create memory leak
Published 2022-10-26 · Modified
5.5EPSS 0.007
CVE-2022-3663
Axiomatic Bento4 MP4fragment Ap4StsdAtom.cpp AP4_StsdAtom null pointer dereference
Published 2022-10-26 · Modified
5.5EPSS 0.007
CVE-2022-3668
Axiomatic Bento4 mp4edit CreateAtomFromStream memory leak
Published 2022-10-26 · Modified
5.5EPSS 0.007
CVE-2022-31287
An issue was discovered in Bento4 v1.2. There is an allocation size request error in /Ap4RtpAtom.cpp.
Published 2022-06-10 · Modified
5.5EPSS 0.007
CVE-2022-31285
An issue was discovered in Bento4 1.2. The allocator is out of memory in /Source/C++/Core/Ap4Array.h.
Published 2022-06-10 · Modified
5.5EPSS 0.007
CVE-2022-31282
Bento4 MP4Dump v1.2 was discovered to contain a segmentation violation via an unknown address at /Source/C++/Core/Ap4DataBuffer.cpp:175.
Published 2022-06-10 · Modified
5.5EPSS 0.007
CVE-2022-29017
Bento4 v1.6.0.0 was discovered to contain a segmentation fault via the component /x86_64/multiarch/strlen-avx2.S.
Published 2022-05-16 · Modified
5.5EPSS 0.006
CVE-2021-40943
In Bento4 1.6.0-638, there is a null pointer reference in the function AP4_DescriptorListInspector::Action function in Ap4Descriptor.h:124 , as demonstrated by GPAC. This can cause a denial of service (DOS).
Published 2022-06-28 · Modified
5.5EPSS 0.006
CVE-2022-41847
An issue was discovered in Bento4 1.6.0-639. A memory leak exists in AP4_StdcFileByteStream::Create(AP4_FileByteStream*, char const*, AP4_FileByteStream::Mode, AP4_ByteStream*&) in System/StdC/Ap4StdCFileByteStream.cpp.
Published 2022-09-30 · Modified
5.5EPSS 0.004
CVE-2022-41845
An issue was discovered in Bento4 1.6.0-639. There ie excessive memory consumption in the function AP4_Array<AP4_ElstEntry>::EnsureCapacity in Core/Ap4Array.h.
Published 2022-09-30 · Modified
5.5EPSS 0.003
CVE-2022-40775
An issue was discovered in Bento4 through 1.6.0-639. A NULL pointer dereference occurs in AP4_StszAtom::WriteFields.
Published 2022-09-18 · Modified
5.5EPSS 0.003
CVE-2022-40774
An issue was discovered in Bento4 through 1.6.0-639. There is a NULL pointer dereference in AP4_StszAtom::GetSampleSize.
Published 2022-09-18 · Modified
5.5EPSS 0.003
CVE-2023-29575
Bento4 v1.6.0-639 was discovered to contain an out-of-memory bug in the mp42aac component.
Published 2023-04-21 · Modified
5.5EPSS 0.003
CVE-2022-41846
An issue was discovered in Bento4 1.6.0-639. There ie excessive memory consumption in the function AP4_DataBuffer::ReallocateBuffer in Core/Ap4DataBuffer.cpp.
Published 2022-09-30 · Modified
5.5EPSS 0.003
CVE-2023-29573
Bento4 v1.6.0-639 was discovered to contain an out-of-memory bug in the mp4info component.
Published 2023-04-13 · Modified
5.5EPSS 0.003
CVE-2023-29576
Bento4 v1.6.0-639 was discovered to contain a segmentation violation via the AP4_TrunAtom::SetDataOffset(int) function in Ap4TrunAtom.h.
Published 2023-04-11 · Modified
5.5EPSS 0.003
CVE-2022-40884
Bento4 1.6.0 has memory leaks via the mp4fragment.
Published 2022-10-19 · Modified
5.5EPSS 0.003
CVE-2023-29574
Bento4 v1.6.0-639 was discovered to contain an out-of-memory bug in the mp42avc component.
Published 2023-04-12 · Modified
5.5EPSS 0.003
CVE-2022-35165
An issue in AP4_SgpdAtom::AP4_SgpdAtom() of Bento4-1.6.0-639 allows attackers to cause a Denial of Service (DoS) via a crafted mp4 input.
Published 2022-08-18 · Modified
5.5EPSS 0.003
CVE-2023-38666
Bento4 v1.6.0-639 was discovered to contain a segmentation violation via the AP4_Processor::ProcessFragments function in mp4encrypt.
Published 2023-08-22 · Modified
5.5EPSS 0.003
CVE-2022-41841
An issue was discovered in Bento4 through 1.6.0-639. A NULL pointer dereference occurs in AP4_File::ParseStream in Core/Ap4File.cpp, which is called from AP4_File::AP4_File.
Published 2022-09-30 · Modified
5.5EPSS 0.003
CVE-2024-25453
Bento4 v1.6.0-640 was discovered to contain a NULL pointer dereference via the AP4_StszAtom::GetSampleSize() function.
Published 2024-02-09 · Modified
5.5EPSS 0.003
CVE-2024-25454
Bento4 v1.6.0-640 was discovered to contain a NULL pointer dereference via the AP4_DescriptorFinder::Test() function.
Published 2024-02-09 · Modified
5.5EPSS 0.002
CVE-2024-25452
Bento4 v1.6.0-640 was discovered to contain an out-of-memory bug via the AP4_UrlAtom::AP4_UrlAtom() function.
Published 2024-02-09 · Modified
5.5EPSS 0.002
CVE-2022-40885
Bento4 v1.6.0-639 has a memory allocation issue that can cause denial of service.
Published 2022-10-19 · Modified
5.5EPSS 0.002
CVE-2025-25946
An issue in Bento4 v1.6.0-641 allows an attacker to cause a memory leak via Ap4Marlin.cpp and Ap4Processor.cpp, specifically in AP4_MarlinIpmpEncryptingProcessor::Initialize and AP4_Processor::Process, during the execution of mp4encrypt with a specially crafted MP4 input file.
Published 2025-02-19 · Analyzed
5.5EPSS 0.002
CVE-2025-25947
An issue in Bento4 v1.6.0-641 allows an attacker to trigger a segmentation fault via Ap4Atom.cpp, specifically in AP4_AtomParent::RemoveChild, during the execution of mp4encrypt with a specially crafted MP4 input file.
Published 2025-02-19 · Analyzed
5.5EPSS 0.002
CVE-2024-30808
An issue was discovered in Bento4 v1.6.0-641-2-g1529b83. There is a heap-use-after-free in AP4_SubStream::~AP4_SubStream at Ap4ByteStream.cpp, leading to a Denial of Service (DoS), as demonstrated by mp42ts.
Published 2024-04-02 · Analyzed
2.7EPSS 0.006
← Prev4 / 4