VendorsAxiosysbento4any version
Vulnerabilities

Axiosys Axiomatic Systems Bento4 any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

23CVEs
CVE-2021-32265
An issue was discovered in Bento4 through v1.6.0-637. A global-buffer-overflow exists in the function AP4_MemoryByteStream::WritePartial() located in Ap4ByteStream.cpp. It allows an attacker to cause code execution or information disclosure.
Published 2021-09-20 · Modified
8.8EPSS 0.016
CVE-2022-4584
Axiomatic Bento4 mp42aac heap-based overflow
Published 2022-12-17 · Modified
8.8EPSS 0.010
CVE-2020-23332
A heap-based buffer overflow exists in the AP4_StdcFileByteStream::ReadPartial component located in /StdC/Ap4StdCFileByteStream.cpp of Bento4 version 06c39d9. This issue can lead to a denial of service (DOS).
Published 2021-08-17 · Modified
7.5EPSS 0.013
CVE-2020-23330
An issue was discovered in Bento4 version 06c39d9. A NULL pointer dereference exists in the AP4_Stz2Atom::GetSampleSize component located in /Core/Ap4Stz2Atom.cpp. It allows an attacker to cause a denial of service (DOS).
Published 2021-08-17 · Modified
7.5EPSS 0.013
CVE-2020-23334
A WRITE memory access in the AP4_NullTerminatedStringAtom::AP4_NullTerminatedStringAtom component of Bento4 version 06c39d9 can lead to a segmentation fault.
Published 2021-08-17 · Modified
7.5EPSS 0.013
CVE-2020-23331
An issue was discovered in Bento4 version 06c39d9. A NULL pointer dereference exists in the AP4_DescriptorListWriter::Action component located in /Core/Ap4Descriptor.h. It allows an attacker to cause a denial of service (DOS).
Published 2021-08-17 · Modified
7.5EPSS 0.012
CVE-2020-23333
A heap-based buffer overflow exists in the AP4_CttsAtom::AP4_CttsAtom component located in /Core/Ap4Utils.h of Bento4 version 06c39d9. This can lead to a denial of service (DOS).
Published 2021-08-17 · Modified
7.5EPSS 0.012
CVE-2025-0751
Axiomatic Bento4 mp42aac ReadBits heap-based overflow
Published 2025-01-27 · Analyzed
7.5EPSS 0.005
CVE-2025-0753
Axiomatic Bento4 mp42aac ReadPartial heap-based overflow
Published 2025-01-27 · Analyzed
7.5EPSS 0.005
CVE-2022-3807
Axiomatic Bento4 Incomplete Fix CVE-2019-13238 resource consumption
Published 2022-11-01 · Modified
6.5EPSS 0.011
CVE-2021-35306
An issue was discovered in Bento4 through v1.6.0-636. A NULL pointer dereference exists in the function AP4_StszAtom::WriteFields located in Ap4StszAtom.cpp. It allows an attacker to cause a denial of service (DOS).
Published 2021-08-05 · Modified
6.5EPSS 0.010
CVE-2021-35307
An issue was discovered in Bento4 through v1.6.0-636. A NULL pointer dereference exists in the AP4_DescriptorFinder::Test component located in /Core/Ap4Descriptor.h. It allows an attacker to cause a denial of service (DOS).
Published 2021-08-05 · Modified
6.5EPSS 0.010
CVE-2022-3810
Axiomatic Bento4 mp42hevc Mp42Hevc.cpp AP4_File denial of service
Published 2022-11-01 · Modified
6.5EPSS 0.009
CVE-2022-3809
Axiomatic Bento4 mp4tag Mp4Tag.cpp ParseCommandLine denial of service
Published 2022-11-01 · Modified
6.5EPSS 0.008
CVE-2022-40738
An issue was discovered in Bento4 through 1.6.0-639. A NULL pointer dereference occurs in AP4_DescriptorListWriter::Action in Core/Ap4Descriptor.h, called from AP4_EsDescriptor::WriteFields and AP4_Expandable::Write.
Published 2022-09-15 · Modified
6.5EPSS 0.007
CVE-2022-40737
An issue was discovered in Bento4 through 1.6.0-639. A buffer over-read exists in the function AP4_StdcFileByteStream::WritePartial located in System/StdC/Ap4StdCFileByteStream.cpp, called from AP4_ByteStream::Write and AP4_HdlrAtom::WriteFields.
Published 2022-09-15 · Modified
6.5EPSS 0.007
CVE-2025-0870
Axiomatic Bento4 Ap4DataBuffer.h GetData heap-based overflow
Published 2025-01-30 · Analyzed
6.3EPSS 0.005
CVE-2025-8537
Axiomatic Bento4 mp4decrypt Mp4Decrypt.cpp SetDataSize allocation of resources
Published 2025-08-05 · Analyzed
5.9EPSS 0.006
CVE-2017-12475
The AP4_Processor::Process function in Core/Ap4Processor.cpp in Bento4 mp4encrypt before 1.5.0-616 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted mp4 file.
Published 2017-09-06 · Modified
5.5EPSS 0.012
CVE-2020-23912
An issue was discovered in Bento4 through v1.6.0-637. A NULL pointer dereference exists in the function AP4_StszAtom::GetSampleSize() located in Ap4StszAtom.cpp. It allows an attacker to cause Denial of Service.
Published 2021-04-21 · Modified
5.5EPSS 0.007
CVE-2022-40774
An issue was discovered in Bento4 through 1.6.0-639. There is a NULL pointer dereference in AP4_StszAtom::GetSampleSize.
Published 2022-09-18 · Modified
5.5EPSS 0.003
CVE-2022-40775
An issue was discovered in Bento4 through 1.6.0-639. A NULL pointer dereference occurs in AP4_StszAtom::WriteFields.
Published 2022-09-18 · Modified
5.5EPSS 0.003
CVE-2022-41841
An issue was discovered in Bento4 through 1.6.0-639. A NULL pointer dereference occurs in AP4_File::ParseStream in Core/Ap4File.cpp, which is called from AP4_File::AP4_File.
Published 2022-09-30 · Modified
5.5EPSS 0.003