axiosys CVE Vulnerabilities & Metrics

Focus on axiosys vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About axiosys Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with axiosys. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total axiosys CVEs: 140
Earliest CVE date: 06 Sep 2017, 08:29 UTC
Latest CVE date: 30 Jan 2025, 13:15 UTC

Latest CVE reference: CVE-2025-0870

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 3

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): -100.0%
Year Variation (Calendar): -70.0%

Month Growth Rate (30-day Rolling): -100.0%
Year Growth Rate (365-day Rolling): -70.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical axiosys CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 3.02

Max CVSS: 7.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 60
4.0-6.9 74
7.0-8.9 6
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS axiosys CVEs

These are the five CVEs with the highest CVSS scores for axiosys, sorted by severity first and recency.

All CVEs for axiosys

CVE-2025-0870 axiosys vulnerability CVSS: 5.1 30 Jan 2025, 13:15 UTC

A vulnerability was found in Axiomatic Bento4 up to 1.6.0-641. It has been rated as critical. Affected by this issue is the function AP4_DataBuffer::GetData in the library Ap4DataBuffer.h. The manipulation leads to heap-based buffer overflow. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available.

CVE-2025-0753 axiosys vulnerability CVSS: 7.5 27 Jan 2025, 21:15 UTC

A vulnerability classified as critical was found in Axiomatic Bento4 up to 1.6.0. This vulnerability affects the function AP4_StdcFileByteStream::ReadPartial of the component mp42aac. The manipulation leads to heap-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-0751 axiosys vulnerability CVSS: 7.5 27 Jan 2025, 20:15 UTC

A vulnerability classified as critical has been found in Axiomatic Bento4 up to 1.6.0. This affects the function AP4_BitReader::ReadBits of the component mp42aac. The manipulation leads to heap-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-24155 axiosys vulnerability CVSS: 0 29 Feb 2024, 01:44 UTC

Bento4 v1.5.1-628 contains a Memory leak on AP4_Movie::AP4_Movie, parsing tracks and added into m_Tracks list, but mp42aac cannot correctly delete when we got an no audio track found error. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted mp4 file.

CVE-2024-25454 axiosys vulnerability CVSS: 0 09 Feb 2024, 15:15 UTC

Bento4 v1.6.0-640 was discovered to contain a NULL pointer dereference via the AP4_DescriptorFinder::Test() function.

CVE-2024-25453 axiosys vulnerability CVSS: 0 09 Feb 2024, 15:15 UTC

Bento4 v1.6.0-640 was discovered to contain a NULL pointer dereference via the AP4_StszAtom::GetSampleSize() function.

CVE-2024-25452 axiosys vulnerability CVSS: 0 09 Feb 2024, 15:15 UTC

Bento4 v1.6.0-640 was discovered to contain an out-of-memory bug via the AP4_UrlAtom::AP4_UrlAtom() function.

CVE-2024-25451 axiosys vulnerability CVSS: 0 09 Feb 2024, 15:15 UTC

Bento4 v1.6.0-640 was discovered to contain an out-of-memory bug via the AP4_DataBuffer::ReallocateBuffer() function.

CVE-2023-38666 axiosys vulnerability CVSS: 0 22 Aug 2023, 19:16 UTC

Bento4 v1.6.0-639 was discovered to contain a segmentation violation via the AP4_Processor::ProcessFragments function in mp4encrypt.

CVE-2023-29575 axiosys vulnerability CVSS: 0 21 Apr 2023, 14:15 UTC

Bento4 v1.6.0-639 was discovered to contain an out-of-memory bug in the mp42aac component.

CVE-2023-29573 axiosys vulnerability CVSS: 0 13 Apr 2023, 20:15 UTC

Bento4 v1.6.0-639 was discovered to contain an out-of-memory bug in the mp4info component.

CVE-2023-29574 axiosys vulnerability CVSS: 0 12 Apr 2023, 13:15 UTC

Bento4 v1.6.0-639 was discovered to contain an out-of-memory bug in the mp42avc component.

CVE-2023-29576 axiosys vulnerability CVSS: 0 11 Apr 2023, 21:15 UTC

Bento4 v1.6.0-639 was discovered to contain a segmentation violation via the AP4_TrunAtom::SetDataOffset(int) function in Ap4TrunAtom.h.

CVE-2022-4584 axiosys vulnerability CVSS: 7.5 17 Dec 2022, 13:15 UTC

A vulnerability was found in Axiomatic Bento4 up to 1.6.0-639. It has been rated as critical. Affected by this issue is some unknown functionality of the component mp42aac. The manipulation leads to heap-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-216170 is the identifier assigned to this vulnerability.

CVE-2022-3974 axiosys vulnerability CVSS: 0 13 Nov 2022, 10:15 UTC

A vulnerability classified as critical was found in Axiomatic Bento4. Affected by this vulnerability is the function AP4_StdcFileByteStream::ReadPartial of the file Ap4StdCFileByteStream.cpp of the component mp4info. The manipulation leads to heap-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-213553 was assigned to this vulnerability.

CVE-2022-3810 axiosys vulnerability CVSS: 0 02 Nov 2022, 13:15 UTC

A vulnerability was found in Axiomatic Bento4. It has been classified as problematic. This affects the function AP4_File::AP4_File of the file Mp42Hevc.cpp of the component mp42hevc. The manipulation leads to denial of service. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-212667.

CVE-2022-3809 axiosys vulnerability CVSS: 0 02 Nov 2022, 13:15 UTC

A vulnerability was found in Axiomatic Bento4 and classified as problematic. Affected by this issue is the function ParseCommandLine of the file Mp4Tag/Mp4Tag.cpp of the component mp4tag. The manipulation leads to denial of service. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-212666 is the identifier assigned to this vulnerability.

CVE-2022-3817 axiosys vulnerability CVSS: 0 01 Nov 2022, 22:15 UTC

A vulnerability has been found in Axiomatic Bento4 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component mp4mux. The manipulation leads to memory leak. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-212683.

CVE-2022-3816 axiosys vulnerability CVSS: 0 01 Nov 2022, 22:15 UTC

A vulnerability, which was classified as problematic, was found in Axiomatic Bento4. Affected is an unknown function of the component mp4decrypt. The manipulation leads to memory leak. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-212682 is the identifier assigned to this vulnerability.

CVE-2022-3815 axiosys vulnerability CVSS: 0 01 Nov 2022, 22:15 UTC

A vulnerability, which was classified as problematic, has been found in Axiomatic Bento4. This issue affects some unknown processing of the component mp4decrypt. The manipulation leads to memory leak. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-212681 was assigned to this vulnerability.

CVE-2022-3814 axiosys vulnerability CVSS: 0 01 Nov 2022, 22:15 UTC

A vulnerability classified as problematic was found in Axiomatic Bento4. This vulnerability affects unknown code of the component mp4decrypt. The manipulation leads to memory leak. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-212680.

CVE-2022-3813 axiosys vulnerability CVSS: 0 01 Nov 2022, 22:15 UTC

A vulnerability classified as problematic has been found in Axiomatic Bento4. This affects an unknown part of the component mp4edit. The manipulation leads to memory leak. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-212679.

CVE-2022-3812 axiosys vulnerability CVSS: 0 01 Nov 2022, 22:15 UTC

A vulnerability was found in Axiomatic Bento4. It has been rated as problematic. Affected by this issue is the function AP4_ContainerAtom::AP4_ContainerAtom of the component mp4encrypt. The manipulation leads to memory leak. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-212678 is the identifier assigned to this vulnerability.

CVE-2022-3807 axiosys vulnerability CVSS: 0 01 Nov 2022, 20:15 UTC

A vulnerability was found in Axiomatic Bento4. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Incomplete Fix CVE-2019-13238. The manipulation leads to resource consumption. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-212660.

CVE-2022-3785 axiosys vulnerability CVSS: 0 31 Oct 2022, 21:15 UTC

A vulnerability, which was classified as critical, has been found in Axiomatic Bento4. Affected by this issue is the function AP4_DataBuffer::SetDataSize of the component Avcinfo. The manipulation leads to heap-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-212564.

CVE-2022-3784 axiosys vulnerability CVSS: 0 31 Oct 2022, 21:15 UTC

A vulnerability classified as critical was found in Axiomatic Bento4 5e7bb34. Affected by this vulnerability is the function AP4_Mp4AudioDsiParser::ReadBits of the file Ap4Mp4AudioInfo.cpp of the component mp4hls. The manipulation leads to heap-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-212563.

CVE-2022-3670 axiosys vulnerability CVSS: 0 26 Oct 2022, 19:15 UTC

A vulnerability was found in Axiomatic Bento4. It has been classified as critical. Affected is the function WriteSample of the component mp42hevc. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-212010 is the identifier assigned to this vulnerability.

CVE-2022-3669 axiosys vulnerability CVSS: 0 26 Oct 2022, 19:15 UTC

A vulnerability was found in Axiomatic Bento4 and classified as problematic. This issue affects the function AP4_AvccAtom::Create of the component mp4edit. The manipulation leads to memory leak. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-212009 was assigned to this vulnerability.

CVE-2022-3668 axiosys vulnerability CVSS: 0 26 Oct 2022, 19:15 UTC

A vulnerability has been found in Axiomatic Bento4 and classified as problematic. This vulnerability affects the function AP4_AtomFactory::CreateAtomFromStream of the component mp4edit. The manipulation leads to memory leak. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-212008.

CVE-2022-3667 axiosys vulnerability CVSS: 0 26 Oct 2022, 19:15 UTC

A vulnerability, which was classified as critical, was found in Axiomatic Bento4. This affects the function AP4_MemoryByteStream::WritePartial of the file Ap4ByteStream.cpp of the component mp42aac. The manipulation leads to heap-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-212007.

CVE-2022-3666 axiosys vulnerability CVSS: 0 26 Oct 2022, 19:15 UTC

A vulnerability, which was classified as critical, has been found in Axiomatic Bento4. Affected by this issue is the function AP4_LinearReader::Advance of the file Ap4LinearReader.cpp of the component mp42ts. The manipulation leads to use after free. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-212006 is the identifier assigned to this vulnerability.

CVE-2022-3665 axiosys vulnerability CVSS: 0 26 Oct 2022, 19:15 UTC

A vulnerability classified as critical was found in Axiomatic Bento4. Affected by this vulnerability is an unknown functionality of the file AvcInfo.cpp of the component avcinfo. The manipulation leads to heap-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-212005 was assigned to this vulnerability.

CVE-2022-3664 axiosys vulnerability CVSS: 0 26 Oct 2022, 19:15 UTC

A vulnerability classified as critical has been found in Axiomatic Bento4. Affected is the function AP4_BitStream::WriteBytes of the file Ap4BitStream.cpp of the component avcinfo. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-212004.

CVE-2022-3663 axiosys vulnerability CVSS: 0 26 Oct 2022, 19:15 UTC

A vulnerability was found in Axiomatic Bento4. It has been rated as problematic. This issue affects the function AP4_StsdAtom of the file Ap4StsdAtom.cpp of the component MP4fragment. The manipulation leads to null pointer dereference. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-212003.

CVE-2022-3662 axiosys vulnerability CVSS: 0 26 Oct 2022, 19:15 UTC

A vulnerability was found in Axiomatic Bento4. It has been declared as critical. This vulnerability affects the function GetOffset of the file Ap4Sample.h of the component mp42hls. The manipulation leads to use after free. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-212002 is the identifier assigned to this vulnerability.

CVE-2022-40885 axiosys vulnerability CVSS: 0 19 Oct 2022, 18:15 UTC

Bento4 v1.6.0-639 has a memory allocation issue that can cause denial of service.

CVE-2022-40884 axiosys vulnerability CVSS: 0 19 Oct 2022, 18:15 UTC

Bento4 1.6.0 has memory leaks via the mp4fragment.

CVE-2022-43038 axiosys vulnerability CVSS: 0 19 Oct 2022, 14:15 UTC

Bento4 v1.6.0-639 was discovered to contain a heap overflow via the AP4_BitReader::ReadCache() function in mp42ts.

CVE-2022-43037 axiosys vulnerability CVSS: 0 19 Oct 2022, 14:15 UTC

An issue was discovered in Bento4 1.6.0-639. There is a memory leak in the function AP4_File::ParseStream in /Core/Ap4File.cpp.

CVE-2022-43035 axiosys vulnerability CVSS: 0 19 Oct 2022, 14:15 UTC

An issue was discovered in Bento4 v1.6.0-639. There is a heap-buffer-overflow in AP4_Dec3Atom::AP4_Dec3Atom at Ap4Dec3Atom.cpp, leading to a Denial of Service (DoS), as demonstrated by mp42aac.

CVE-2022-43034 axiosys vulnerability CVSS: 0 19 Oct 2022, 14:15 UTC

An issue was discovered in Bento4 v1.6.0-639. There is a heap buffer overflow vulnerability in the AP4_BitReader::SkipBits(unsigned int) function in mp42ts.

CVE-2022-43033 axiosys vulnerability CVSS: 0 19 Oct 2022, 14:15 UTC

An issue was discovered in Bento4 1.6.0-639. There is a bad free in the component AP4_HdlrAtom::~AP4_HdlrAtom() which allows attackers to cause a Denial of Service (DoS) via a crafted input.

CVE-2022-43032 axiosys vulnerability CVSS: 0 19 Oct 2022, 14:15 UTC

An issue was discovered in Bento4 v1.6.0-639. There is a memory leak in AP4_DescriptorFactory::CreateDescriptorFromStream in Core/Ap4DescriptorFactory.cpp, as demonstrated by mp42aac.

CVE-2022-41430 axiosys vulnerability CVSS: 0 03 Oct 2022, 14:15 UTC

Bento4 v1.6.0-639 was discovered to contain a heap overflow via the AP4_BitReader::ReadBit function in mp4mux.

CVE-2022-41429 axiosys vulnerability CVSS: 0 03 Oct 2022, 14:15 UTC

Bento4 v1.6.0-639 was discovered to contain a heap overflow via the AP4_Atom::TypeFromString function in mp4tag.

CVE-2022-41428 axiosys vulnerability CVSS: 0 03 Oct 2022, 14:15 UTC

Bento4 v1.6.0-639 was discovered to contain a heap overflow via the AP4_BitReader::ReadBits function in mp4mux.

CVE-2022-41427 axiosys vulnerability CVSS: 0 03 Oct 2022, 14:15 UTC

Bento4 v1.6.0-639 was discovered to contain a memory leak in the AP4_AvcFrameParser::Feed function in mp4mux.

CVE-2022-41426 axiosys vulnerability CVSS: 0 03 Oct 2022, 14:15 UTC

Bento4 v1.6.0-639 was discovered to contain a memory leak via the AP4_AtomFactory::CreateAtomFromStream function in mp4split.

CVE-2022-41425 axiosys vulnerability CVSS: 0 03 Oct 2022, 14:15 UTC

Bento4 v1.6.0-639 was discovered to contain a segmentation violation via the AP4_Processor::ProcessFragments function in mp4decrypt.

CVE-2022-41424 axiosys vulnerability CVSS: 0 03 Oct 2022, 14:15 UTC

Bento4 v1.6.0-639 was discovered to contain a memory leak via the AP4_SttsAtom::Create function in mp42hls.

CVE-2022-41423 axiosys vulnerability CVSS: 0 03 Oct 2022, 14:15 UTC

Bento4 v1.6.0-639 was discovered to contain a segmentation violation in the mp4fragment component.

CVE-2022-41419 axiosys vulnerability CVSS: 0 03 Oct 2022, 14:15 UTC

Bento4 v1.6.0-639 was discovered to contain a memory leak via the AP4_Processor::Process function in the mp4encrypt binary.

CVE-2022-41847 axiosys vulnerability CVSS: 0 30 Sep 2022, 05:15 UTC

An issue was discovered in Bento4 1.6.0-639. A memory leak exists in AP4_StdcFileByteStream::Create(AP4_FileByteStream*, char const*, AP4_FileByteStream::Mode, AP4_ByteStream*&) in System/StdC/Ap4StdCFileByteStream.cpp.

CVE-2022-41846 axiosys vulnerability CVSS: 0 30 Sep 2022, 05:15 UTC

An issue was discovered in Bento4 1.6.0-639. There ie excessive memory consumption in the function AP4_DataBuffer::ReallocateBuffer in Core/Ap4DataBuffer.cpp.

CVE-2022-41845 axiosys vulnerability CVSS: 0 30 Sep 2022, 05:15 UTC

An issue was discovered in Bento4 1.6.0-639. There ie excessive memory consumption in the function AP4_Array<AP4_ElstEntry>::EnsureCapacity in Core/Ap4Array.h.

CVE-2022-41841 axiosys vulnerability CVSS: 0 30 Sep 2022, 05:15 UTC

An issue was discovered in Bento4 through 1.6.0-639. A NULL pointer dereference occurs in AP4_File::ParseStream in Core/Ap4File.cpp, which is called from AP4_File::AP4_File.

CVE-2022-40775 axiosys vulnerability CVSS: 0 18 Sep 2022, 19:15 UTC

An issue was discovered in Bento4 through 1.6.0-639. A NULL pointer dereference occurs in AP4_StszAtom::WriteFields.

CVE-2022-40774 axiosys vulnerability CVSS: 0 18 Sep 2022, 19:15 UTC

An issue was discovered in Bento4 through 1.6.0-639. There is a NULL pointer dereference in AP4_StszAtom::GetSampleSize.

CVE-2022-40738 axiosys vulnerability CVSS: 0 15 Sep 2022, 04:15 UTC

An issue was discovered in Bento4 through 1.6.0-639. A NULL pointer dereference occurs in AP4_DescriptorListWriter::Action in Core/Ap4Descriptor.h, called from AP4_EsDescriptor::WriteFields and AP4_Expandable::Write.

CVE-2022-40737 axiosys vulnerability CVSS: 0 15 Sep 2022, 04:15 UTC

An issue was discovered in Bento4 through 1.6.0-639. A buffer over-read exists in the function AP4_StdcFileByteStream::WritePartial located in System/StdC/Ap4StdCFileByteStream.cpp, called from AP4_ByteStream::Write and AP4_HdlrAtom::WriteFields.

CVE-2022-40736 axiosys vulnerability CVSS: 0 15 Sep 2022, 04:15 UTC

An issue was discovered in Bento4 1.6.0-639. There ie excessive memory consumption in AP4_CttsAtom::Create in Core/Ap4CttsAtom.cpp.

CVE-2022-40439 axiosys vulnerability CVSS: 0 14 Sep 2022, 21:15 UTC

An memory leak issue was discovered in AP4_StdcFileByteStream::Create in mp42ts in Bento4 v1.6.0-639, allows attackers to cause a denial of service via a crafted file.

CVE-2022-40438 axiosys vulnerability CVSS: 0 14 Sep 2022, 21:15 UTC

Buffer overflow vulnerability in function AP4_MemoryByteStream::WritePartial in mp42aac in Bento4 v1.6.0-639, allows attackers to cause a denial of service via a crafted file.

CVE-2022-35165 axiosys vulnerability CVSS: 0 18 Aug 2022, 05:15 UTC

An issue in AP4_SgpdAtom::AP4_SgpdAtom() of Bento4-1.6.0-639 allows attackers to cause a Denial of Service (DoS) via a crafted mp4 input.

CVE-2021-40943 axiosys vulnerability CVSS: 4.3 28 Jun 2022, 13:15 UTC

In Bento4 1.6.0-638, there is a null pointer reference in the function AP4_DescriptorListInspector::Action function in Ap4Descriptor.h:124 , as demonstrated by GPAC. This can cause a denial of service (DOS).

CVE-2021-40941 axiosys vulnerability CVSS: 5.0 27 Jun 2022, 18:15 UTC

In Bento4 1.6.0-638, there is an allocator is out of memory in the function AP4_Array<AP4_TrunAtom::Entry>::EnsureCapacity in Ap4Array.h:172, as demonstrated by GPAC. This can cause a denial of service (DOS).

CVE-2022-31287 axiosys vulnerability CVSS: 4.3 10 Jun 2022, 18:15 UTC

An issue was discovered in Bento4 v1.2. There is an allocation size request error in /Ap4RtpAtom.cpp.

CVE-2022-31285 axiosys vulnerability CVSS: 4.3 10 Jun 2022, 18:15 UTC

An issue was discovered in Bento4 1.2. The allocator is out of memory in /Source/C++/Core/Ap4Array.h.

CVE-2022-31282 axiosys vulnerability CVSS: 4.3 10 Jun 2022, 18:15 UTC

Bento4 MP4Dump v1.2 was discovered to contain a segmentation violation via an unknown address at /Source/C++/Core/Ap4DataBuffer.cpp:175.

CVE-2022-29017 axiosys vulnerability CVSS: 4.3 16 May 2022, 14:15 UTC

Bento4 v1.6.0.0 was discovered to contain a segmentation fault via the component /x86_64/multiarch/strlen-avx2.S.

CVE-2022-27607 axiosys vulnerability CVSS: 5.8 21 Mar 2022, 23:15 UTC

Bento4 1.6.0-639 has a heap-based buffer over-read in the AP4_HvccAtom class, a different issue than CVE-2018-14531.

CVE-2021-32265 axiosys vulnerability CVSS: 6.8 20 Sep 2021, 16:15 UTC

An issue was discovered in Bento4 through v1.6.0-637. A global-buffer-overflow exists in the function AP4_MemoryByteStream::WritePartial() located in Ap4ByteStream.cpp. It allows an attacker to cause code execution or information disclosure.

CVE-2018-10790 axiosys vulnerability CVSS: 5.0 25 Aug 2021, 14:15 UTC

The AP4_CttsAtom class in Core/Ap4CttsAtom.cpp in Bento4 1.5.1.0 allows remote attackers to cause a denial of service (application crash), related to a memory allocation failure, as demonstrated by mp2aac.

CVE-2020-23334 axiosys vulnerability CVSS: 5.0 17 Aug 2021, 22:15 UTC

A WRITE memory access in the AP4_NullTerminatedStringAtom::AP4_NullTerminatedStringAtom component of Bento4 version 06c39d9 can lead to a segmentation fault.

CVE-2020-23333 axiosys vulnerability CVSS: 5.0 17 Aug 2021, 22:15 UTC

A heap-based buffer overflow exists in the AP4_CttsAtom::AP4_CttsAtom component located in /Core/Ap4Utils.h of Bento4 version 06c39d9. This can lead to a denial of service (DOS).

CVE-2020-23332 axiosys vulnerability CVSS: 5.0 17 Aug 2021, 22:15 UTC

A heap-based buffer overflow exists in the AP4_StdcFileByteStream::ReadPartial component located in /StdC/Ap4StdCFileByteStream.cpp of Bento4 version 06c39d9. This issue can lead to a denial of service (DOS).

CVE-2020-23331 axiosys vulnerability CVSS: 5.0 17 Aug 2021, 22:15 UTC

An issue was discovered in Bento4 version 06c39d9. A NULL pointer dereference exists in the AP4_DescriptorListWriter::Action component located in /Core/Ap4Descriptor.h. It allows an attacker to cause a denial of service (DOS).

CVE-2020-23330 axiosys vulnerability CVSS: 5.0 17 Aug 2021, 22:15 UTC

An issue was discovered in Bento4 version 06c39d9. A NULL pointer dereference exists in the AP4_Stz2Atom::GetSampleSize component located in /Core/Ap4Stz2Atom.cpp. It allows an attacker to cause a denial of service (DOS).

CVE-2020-21066 axiosys vulnerability CVSS: 4.3 13 Aug 2021, 21:15 UTC

An issue was discovered in Bento4 v1.5.1.0. There is a heap-buffer-overflow in AP4_Dec3Atom::AP4_Dec3Atom at Ap4Dec3Atom.cpp, leading to a denial of service (program crash), as demonstrated by mp42aac.

CVE-2021-35307 axiosys vulnerability CVSS: 4.3 05 Aug 2021, 20:15 UTC

An issue was discovered in Bento4 through v1.6.0-636. A NULL pointer dereference exists in the AP4_DescriptorFinder::Test component located in /Core/Ap4Descriptor.h. It allows an attacker to cause a denial of service (DOS).

CVE-2021-35306 axiosys vulnerability CVSS: 4.3 05 Aug 2021, 20:15 UTC

An issue was discovered in Bento4 through v1.6.0-636. A NULL pointer dereference exists in the function AP4_StszAtom::WriteFields located in Ap4StszAtom.cpp. It allows an attacker to cause a denial of service (DOS).

CVE-2020-19722 axiosys vulnerability CVSS: 4.3 13 Jul 2021, 22:15 UTC

An unhandled memory allocation failure in Core/Ap4Atom.cpp of Bento 1.5.1-628 causes a direct copy to NULL pointer dereference, leading to a denial of service (DOS).

CVE-2020-19721 axiosys vulnerability CVSS: 4.3 13 Jul 2021, 22:15 UTC

A heap buffer overflow vulnerability in Ap4TrunAtom.cpp of Bento 1.5.1-628 may lead to an out-of-bounds write while running mp42aac, leading to system crashes and a denial of service (DOS).

CVE-2020-19720 axiosys vulnerability CVSS: 4.3 13 Jul 2021, 22:15 UTC

An unhandled memory allocation failure in Core/AP4IkmsAtom.cpp of Bento 1.5.1-628 causes a NULL pointer dereference, leading to a denial of service (DOS).

CVE-2020-19719 axiosys vulnerability CVSS: 4.3 13 Jul 2021, 22:15 UTC

A buffer overflow vulnerability in Ap4ElstAtom.cpp of Bento 1.5.1-628 leads to a denial of service (DOS).

CVE-2020-19718 axiosys vulnerability CVSS: 4.3 13 Jul 2021, 22:15 UTC

An unhandled memory allocation failure in Core/Ap4Atom.cpp of Bento 1.5.1-628 causes a NULL pointer dereference, leading to a denial of service (DOS).

CVE-2020-19717 axiosys vulnerability CVSS: 4.3 13 Jul 2021, 22:15 UTC

An unhandled memory allocation failure in Core/Ap48bdlAtom.cpp of Bento 1.5.1-628 causes a NULL pointer dereference, leading to a denial of service (DOS).

CVE-2020-23912 axiosys vulnerability CVSS: 4.3 21 Apr 2021, 18:15 UTC

An issue was discovered in Bento4 through v1.6.0-637. A NULL pointer dereference exists in the function AP4_StszAtom::GetSampleSize() located in Ap4StszAtom.cpp. It allows an attacker to cause Denial of Service.

CVE-2019-20092 axiosys vulnerability CVSS: 4.3 30 Dec 2019, 04:15 UTC

An issue was discovered in Bento4 1.5.1.0. There is a NULL pointer dereference in AP4_Descriptor::GetTag in mp42ts when called from AP4_EsDescriptor::GetDecoderConfigDescriptor in Ap4EsDescriptor.cpp.

CVE-2019-20091 axiosys vulnerability CVSS: 4.3 30 Dec 2019, 04:15 UTC

An issue was discovered in Bento4 1.5.1.0. There is a NULL pointer dereference in AP4_Descriptor::GetTag in mp42ts when called from AP4_DecoderConfigDescriptor::GetDecoderSpecificInfoDescriptor in Ap4DecoderConfigDescriptor.cpp.

CVE-2019-20090 axiosys vulnerability CVSS: 6.8 30 Dec 2019, 04:15 UTC

An issue was discovered in Bento4 1.5.1.0. There is a use-after-free in AP4_Sample::GetOffset in Core/Ap4Sample.h when called from Ap4LinearReader.cpp.

CVE-2019-17530 axiosys vulnerability CVSS: 6.8 12 Oct 2019, 20:15 UTC

An issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer over-read in AP4_PrintInspector::AddField in Core/Ap4Atom.cpp when called from AP4_CencSampleEncryption::DoInspectFields in Core/Ap4CommonEncryption.cpp, when called from AP4_Atom::Inspect in Core/Ap4Atom.cpp.

CVE-2019-17529 axiosys vulnerability CVSS: 6.8 12 Oct 2019, 20:15 UTC

An issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer over-read in AP4_CencSampleEncryption::DoInspectFields in Core/Ap4CommonEncryption.cpp when called from AP4_Atom::Inspect in Core/Ap4Atom.cpp.

CVE-2019-17528 axiosys vulnerability CVSS: 4.3 12 Oct 2019, 20:15 UTC

An issue was discovered in Bento4 1.5.1.0. There is a SEGV in the function AP4_TfhdAtom::SetDefaultSampleSize at Core/Ap4TfhdAtom.h when called from AP4_Processor::ProcessFragments in Core/Ap4Processor.cpp.

CVE-2019-17454 axiosys vulnerability CVSS: 4.3 10 Oct 2019, 17:15 UTC

Bento4 1.5.1.0 has a NULL pointer dereference in AP4_Descriptor::GetTag in Core/Ap4Descriptor.h, related to AP4_StsdAtom::GetSampleDescription in Core/Ap4StsdAtom.cpp, as demonstrated by mp4info.

CVE-2019-17453 axiosys vulnerability CVSS: 4.3 10 Oct 2019, 17:15 UTC

Bento4 1.5.1.0 has a NULL pointer dereference in AP4_DescriptorListWriter::Action in Core/Ap4Descriptor.h, related to AP4_IodsAtom::WriteFields in Core/Ap4IodsAtom.cpp, as demonstrated by mp4encrypt or mp4compact.

CVE-2019-17452 axiosys vulnerability CVSS: 4.3 10 Oct 2019, 17:15 UTC

Bento4 1.5.1.0 has a NULL pointer dereference in AP4_DescriptorListInspector::Action in Core/Ap4Descriptor.h, related to AP4_IodsAtom::InspectFields in Core/Ap4IodsAtom.cpp, as demonstrated by mp4dump.

CVE-2019-16349 axiosys vulnerability CVSS: 4.3 16 Sep 2019, 13:15 UTC

Bento4 1.5.1-628 has a NULL pointer dereference in AP4_ByteStream::ReadUI32 in Core/Ap4ByteStream.cpp when called from the AP4_TrunAtom class.

CVE-2019-15050 axiosys vulnerability CVSS: 6.8 14 Aug 2019, 16:15 UTC

An issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer over-read in the AP4_AvccAtom class at Core/Ap4AvccAtom.cpp.

CVE-2019-15049 axiosys vulnerability CVSS: 6.8 14 Aug 2019, 16:15 UTC

An issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer over-read in the AP4_Dec3Atom class at Core/Ap4Dec3Atom.cpp.

CVE-2019-15048 axiosys vulnerability CVSS: 6.8 14 Aug 2019, 16:15 UTC

An issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer overflow in the AP4_RtpAtom class at Core/Ap4RtpAtom.cpp.

CVE-2019-15047 axiosys vulnerability CVSS: 6.8 14 Aug 2019, 16:15 UTC

An issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer over-read in the function AP4_BitReader::SkipBits at Core/Ap4Utils.cpp.

CVE-2019-13959 axiosys vulnerability CVSS: 4.3 18 Jul 2019, 19:15 UTC

In Bento4 1.5.1-627, AP4_DataBuffer::SetDataSize does not handle reallocation failures, leading to a memory copy into a NULL pointer. This is different from CVE-2018-20186.

CVE-2019-13238 axiosys vulnerability CVSS: 5.0 04 Jul 2019, 14:15 UTC

An issue was discovered in Bento4 1.5.1.0. A memory allocation failure is unhandled in Core/Ap4SdpAtom.cpp and leads to crashes. When parsing input video, the program allocates a new buffer to parse an atom in the stream. The unhandled memory allocation failure causes a direct copy to a NULL pointer.

CVE-2019-9544 axiosys vulnerability CVSS: 6.8 01 Mar 2019, 19:29 UTC

An issue was discovered in Bento4 1.5.1-628. An out of bounds write occurs in AP4_CttsTableEntry::AP4_CttsTableEntry() located in Core/Ap4Array.h. It can be triggered by sending a crafted file to (for example) the mp42hls binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact.

CVE-2019-8382 axiosys vulnerability CVSS: 6.8 17 Feb 2019, 02:29 UTC

An issue was discovered in Bento4 1.5.1-628. A NULL pointer dereference occurs in the function AP4_List:Find located in Core/Ap4List.h when called from Core/Ap4Movie.cpp. It can be triggered by sending a crafted file to the mp4dump binary. It allows an attacker to cause a Denial of Service (Segmentation fault) or possibly have unspecified other impact.

CVE-2019-8380 axiosys vulnerability CVSS: 6.8 17 Feb 2019, 02:29 UTC

An issue was discovered in Bento4 1.5.1-628. A NULL pointer dereference occurs in AP4_Track::GetSampleIndexForTimeStampMs() located in Core/Ap4Track.cpp. It can triggered by sending a crafted file to the mp4audioclip binary. It allows an attacker to cause a Denial of Service (Segmentation fault) or possibly have unspecified other impact.

CVE-2019-8378 axiosys vulnerability CVSS: 6.8 17 Feb 2019, 02:29 UTC

An issue was discovered in Bento4 1.5.1-628. A heap-based buffer over-read exists in AP4_BitStream::ReadBytes() in Codecs/Ap4BitStream.cpp, a similar issue to CVE-2017-14645. It can be triggered by sending a crafted file to the aac2mp4 binary. It allows an attacker to cause a Denial of Service (Segmentation fault) or possibly have unspecified other impact.

CVE-2019-7699 axiosys vulnerability CVSS: 4.3 10 Feb 2019, 22:29 UTC

A heap-based buffer over-read occurs in AP4_BitStream::WriteBytes in Codecs/Ap4BitStream.cpp in Bento4 v1.5.1-627. Remote attackers could leverage this vulnerability to cause an exception via crafted mp4 input, which leads to a denial of service.

CVE-2019-7698 axiosys vulnerability CVSS: 4.3 10 Feb 2019, 22:29 UTC

An issue was discovered in AP4_Array<AP4_CttsTableEntry>::EnsureCapacity in Core/Ap4Array.h in Bento4 1.5.1-627. Crafted MP4 input triggers an attempt at excessive memory allocation, as demonstrated by mp42hls, a related issue to CVE-2018-20095.

CVE-2019-7697 axiosys vulnerability CVSS: 4.3 10 Feb 2019, 22:29 UTC

An issue was discovered in Bento4 v1.5.1-627. There is an assertion failure in AP4_AtomListWriter::Action in Core/Ap4Atom.cpp, leading to a denial of service (program crash), as demonstrated by mp42hls.

CVE-2019-6966 axiosys vulnerability CVSS: 4.3 25 Jan 2019, 23:29 UTC

An issue was discovered in Bento4 1.5.1-628. The AP4_ElstAtom class in Core/Ap4ElstAtom.cpp has an attempted excessive memory allocation related to AP4_Array<AP4_ElstEntry>::EnsureCapacity in Core/Ap4Array.h, as demonstrated by mp42hls.

CVE-2019-6132 axiosys vulnerability CVSS: 5.0 11 Jan 2019, 05:29 UTC

An issue was discovered in Bento4 v1.5.1-627. There is a memory leak in AP4_DescriptorFactory::CreateDescriptorFromStream in Core/Ap4DescriptorFactory.cpp when called from the AP4_EsdsAtom class in Core/Ap4EsdsAtom.cpp, as demonstrated by mp42aac.

CVE-2018-20659 axiosys vulnerability CVSS: 4.3 02 Jan 2019, 17:29 UTC

An issue was discovered in Bento4 1.5.1-627. The AP4_StcoAtom class in Core/Ap4StcoAtom.cpp has an attempted excessive memory allocation when called from AP4_AtomFactory::CreateAtomFromStream in Core/Ap4AtomFactory.cpp, as demonstrated by mp42hls.

CVE-2018-20502 axiosys vulnerability CVSS: 4.3 26 Dec 2018, 23:29 UTC

An issue was discovered in Bento4 1.5.1-627. There is an attempt at excessive memory allocation in the AP4_DataBuffer class when called from AP4_HvccAtom::Create in Core/Ap4HvccAtom.cpp.

CVE-2018-20409 axiosys vulnerability CVSS: 4.3 23 Dec 2018, 23:29 UTC

An issue was discovered in Bento4 1.5.1-627. There is a heap-based buffer over-read in AP4_AvccAtom::Create in Core/Ap4AvccAtom.cpp, as demonstrated by mp42hls.

CVE-2018-20408 axiosys vulnerability CVSS: 4.3 23 Dec 2018, 23:29 UTC

An issue was discovered in Bento4 1.5.1-627. There is a memory leak in AP4_StdcFileByteStream::Create in System/StdC/Ap4StdCFileByteStream.cpp, as demonstrated by mp42hls.

CVE-2018-20407 axiosys vulnerability CVSS: 4.3 23 Dec 2018, 23:29 UTC

An issue was discovered in Bento4 1.5.1-627. There is a memory leak in AP4_DescriptorFactory::CreateDescriptorFromStream in Core/Ap4DescriptorFactory.cpp, as demonstrated by mp42hls.

CVE-2018-20186 axiosys vulnerability CVSS: 4.3 17 Dec 2018, 19:29 UTC

An issue was discovered in Bento4 1.5.1-627. AP4_Sample::ReadData in Core/Ap4Sample.cpp allows attackers to trigger an attempted excessive memory allocation, related to AP4_DataBuffer::SetDataSize and AP4_DataBuffer::ReallocateBuffer in Core/Ap4DataBuffer.cpp.

CVE-2018-20095 axiosys vulnerability CVSS: 4.3 12 Dec 2018, 10:29 UTC

An issue was discovered in EnsureCapacity in Core/Ap4Array.h in Bento4 1.5.1-627. Crafted MP4 input triggers an attempt at excessive memory allocation, as demonstrated by mp42hls.

CVE-2018-14590 axiosys vulnerability CVSS: 5.0 24 Jul 2018, 16:29 UTC

An issue has been discovered in Bento4 1.5.1-624. A SEGV can occur in AP4_Processor::ProcessFragments in Core/Ap4Processor.cpp.

CVE-2018-14589 axiosys vulnerability CVSS: 6.8 24 Jul 2018, 16:29 UTC

An issue has been discovered in Bento4 1.5.1-624. AP4_Mp4AudioDsiParser::ReadBits in Codecs/Ap4Mp4AudioInfo.cpp has a heap-based buffer over-read.

CVE-2018-14588 axiosys vulnerability CVSS: 5.0 24 Jul 2018, 16:29 UTC

An issue has been discovered in Bento4 1.5.1-624. A NULL pointer dereference can occur in AP4_DataBuffer::SetData in Core/Ap4DataBuffer.cpp.

CVE-2018-14587 axiosys vulnerability CVSS: 6.8 24 Jul 2018, 16:29 UTC

An issue has been discovered in Bento4 1.5.1-624. AP4_MemoryByteStream::WritePartial in Core/Ap4ByteStream.cpp has a buffer over-read.

CVE-2018-14586 axiosys vulnerability CVSS: 6.8 24 Jul 2018, 16:29 UTC

An issue has been discovered in Bento4 1.5.1-624. A SEGV can occur in AP4_Mpeg2TsAudioSampleStream::WriteSample in Core/Ap4Mpeg2Ts.cpp, a different vulnerability than CVE-2018-14532.

CVE-2018-14585 axiosys vulnerability CVSS: 6.8 24 Jul 2018, 16:29 UTC

An issue has been discovered in Bento4 1.5.1-624. AP4_BytesToUInt16BE in Core/Ap4Utils.h has a heap-based buffer over-read after a call from the AP4_Stz2Atom class.

CVE-2018-14584 axiosys vulnerability CVSS: 6.8 24 Jul 2018, 16:29 UTC

An issue has been discovered in Bento4 1.5.1-624. AP4_AvccAtom::Create in Core/Ap4AvccAtom.cpp has a heap-based buffer over-read.

CVE-2018-14545 axiosys vulnerability CVSS: 4.3 23 Jul 2018, 08:29 UTC

There exists one invalid memory read bug in AP4_SampleDescription::GetType() in Ap4SampleDescription.h in Bento4 1.5.1-624, which can allow attackers to cause a denial-of-service via a crafted mp4 file. This vulnerability can be triggered by the executable mp42ts.

CVE-2018-14544 axiosys vulnerability CVSS: 4.3 23 Jul 2018, 08:29 UTC

There exists one invalid memory read bug in AP4_SampleDescription::GetFormat() in Ap4SampleDescription.h in Bento4 1.5.1-624, which can allow attackers to cause a denial-of-service via a crafted mp4 file. This vulnerability can be triggered by the executable mp42ts.

CVE-2018-14543 axiosys vulnerability CVSS: 4.3 23 Jul 2018, 08:29 UTC

There exists one NULL pointer dereference vulnerability in AP4_JsonInspector::AddField in Ap4Atom.cpp in Bento4 1.5.1-624, which can allow attackers to cause a denial-of-service via a crafted mp4 file. This vulnerability can be triggered by the executable mp4dump.

CVE-2018-14532 axiosys vulnerability CVSS: 7.5 23 Jul 2018, 08:29 UTC

An issue was discovered in Bento4 1.5.1-624. There is a heap-based buffer over-read in AP4_Mpeg2TsVideoSampleStream::WriteSample in Core/Ap4Mpeg2Ts.cpp after a call from Mp42Hls.cpp, a related issue to CVE-2018-13846.

CVE-2018-14531 axiosys vulnerability CVSS: 7.5 23 Jul 2018, 08:29 UTC

An issue was discovered in Bento4 1.5.1-624. There is an unspecified "heap-buffer-overflow" crash in the AP4_HvccAtom class in Core/Ap4HvccAtom.cpp.

CVE-2018-14445 axiosys vulnerability CVSS: 4.3 20 Jul 2018, 13:29 UTC

In Bento4 v1.5.1-624, AP4_File::ParseStream in Ap4File.cpp allows remote attackers to cause a denial of service (infinite loop) via a crafted MP4 file.

CVE-2018-13848 axiosys vulnerability CVSS: 5.0 10 Jul 2018, 18:29 UTC

An issue has been found in Bento4 1.5.1-624. It is a SEGV in AP4_StszAtom::GetSampleSize in Core/Ap4StszAtom.cpp.

CVE-2018-13847 axiosys vulnerability CVSS: 5.0 10 Jul 2018, 18:29 UTC

An issue has been found in Bento4 1.5.1-624. It is a SEGV in AP4_StcoAtom::AdjustChunkOffsets in Core/Ap4StcoAtom.cpp.

CVE-2018-13846 axiosys vulnerability CVSS: 7.5 10 Jul 2018, 18:29 UTC

An issue has been found in Bento4 1.5.1-624. AP4_Mpeg2TsVideoSampleStream::WriteSample in Core/Ap4Mpeg2Ts.cpp has a heap-based buffer over-read after a call from Mp42Ts.cpp, a related issue to CVE-2018-14532.

CVE-2018-5253 axiosys vulnerability CVSS: 6.8 05 Jan 2018, 21:29 UTC

The AP4_FtypAtom class in Core/Ap4FtypAtom.cpp in Bento4 1.5.1.0 has an Infinite loop via a crafted MP4 file that triggers size mishandling.

CVE-2017-14646 axiosys vulnerability CVSS: 5.0 21 Sep 2017, 17:29 UTC

The AP4_AvccAtom and AP4_HvccAtom classes in Bento4 version 1.5.0-617 do not properly validate data sizes, leading to a heap-based buffer over-read and application crash in AP4_DataBuffer::SetData in Core/Ap4DataBuffer.cpp.

CVE-2017-14260 axiosys vulnerability CVSS: 6.8 11 Sep 2017, 09:29 UTC

In the SDK in Bento4 1.5.0-616, the AP4_StssAtom class in Ap4StssAtom.cpp contains a Write Memory Access Violation vulnerability. It is possible to exploit this vulnerability and possibly execute arbitrary code by opening a crafted .MP4 file.

CVE-2017-12475 axiosys vulnerability CVSS: 4.3 06 Sep 2017, 08:29 UTC

The AP4_Processor::Process function in Core/Ap4Processor.cpp in Bento4 mp4encrypt before 1.5.0-616 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted mp4 file.