bento4 CVE Vulnerabilities & Metrics

Focus on bento4 vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About bento4 Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with bento4. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total bento4 CVEs: 13
Earliest CVE date: 11 Sep 2017, 09:29 UTC
Latest CVE date: 21 Sep 2017, 17:29 UTC

Latest CVE reference: CVE-2017-14647

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical bento4 CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 5.65

Max CVSS: 6.8

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 0
4.0-6.9 13
7.0-8.9 0
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS bento4 CVEs

These are the five CVEs with the highest CVSS scores for bento4, sorted by severity first and recency.

All CVEs for bento4

CVE-2017-14647 bento4 vulnerability CVSS: 6.8 21 Sep 2017, 17:29 UTC

A heap-based buffer overflow was discovered in AP4_VisualSampleEntry::ReadFields in Core/Ap4SampleEntry.cpp in Bento4 1.5.0-617. The vulnerability causes an out-of-bounds write, which leads to remote denial of service or possibly code execution.

CVE-2017-14645 bento4 vulnerability CVSS: 4.3 21 Sep 2017, 17:29 UTC

A heap-based buffer over-read was discovered in AP4_BitStream::ReadBytes in Codecs/Ap4BitStream.cpp in Bento4 version 1.5.0-617. The vulnerability causes an application crash, which leads to remote denial of service.

CVE-2017-14644 bento4 vulnerability CVSS: 6.8 21 Sep 2017, 17:29 UTC

A heap-based buffer overflow was discovered in the AP4_HdlrAtom class in Bento4 1.5.0-617. The vulnerability causes an out-of-bounds write, which leads to remote denial of service or possibly code execution.

CVE-2017-14643 bento4 vulnerability CVSS: 4.3 21 Sep 2017, 17:29 UTC

The AP4_HdlrAtom class in Core/Ap4HdlrAtom.cpp in Bento4 version 1.5.0-617 uses an incorrect character data type, leading to a heap-based buffer over-read and application crash in AP4_BytesToUInt32BE in Core/Ap4Utils.h.

CVE-2017-14642 bento4 vulnerability CVSS: 4.3 21 Sep 2017, 17:29 UTC

A NULL pointer dereference was discovered in the AP4_HdlrAtom class in Bento4 version 1.5.0-617. The vulnerability causes a segmentation fault and application crash in AP4_StdcFileByteStream::ReadPartial in System/StdC/Ap4StdCFileByteStream.cpp, which leads to remote denial of service.

CVE-2017-14641 bento4 vulnerability CVSS: 4.3 21 Sep 2017, 17:29 UTC

A NULL pointer dereference was discovered in the AP4_DataAtom class in MetaData/Ap4MetaData.cpp in Bento4 version 1.5.0-617. The vulnerability causes a segmentation fault and application crash, which leads to remote denial of service.

CVE-2017-14640 bento4 vulnerability CVSS: 4.3 21 Sep 2017, 17:29 UTC

A NULL pointer dereference was discovered in AP4_AtomSampleTable::GetSample in Core/Ap4AtomSampleTable.cpp in Bento4 version 1.5.0-617. The vulnerability causes a segmentation fault and application crash, which leads to remote denial of service.

CVE-2017-14639 bento4 vulnerability CVSS: 6.8 21 Sep 2017, 17:29 UTC

AP4_VisualSampleEntry::ReadFields in Core/Ap4SampleEntry.cpp in Bento4 1.5.0-617 uses incorrect character data types, which causes a stack-based buffer underflow and out-of-bounds write, leading to denial of service (application crash) or possibly unspecified other impact.

CVE-2017-14638 bento4 vulnerability CVSS: 4.3 21 Sep 2017, 17:29 UTC

AP4_AtomFactory::CreateAtomFromStream in Core/Ap4AtomFactory.cpp in Bento4 version 1.5.0-617 has missing NULL checks, leading to a NULL pointer dereference, segmentation fault, and application crash in AP4_Atom::SetType in Core/Ap4Atom.h.

CVE-2017-14261 bento4 vulnerability CVSS: 6.8 11 Sep 2017, 09:29 UTC

In the SDK in Bento4 1.5.0-616, the AP4_StszAtom class in Ap4StszAtom.cpp file contains a Read Memory Access Violation vulnerability. It is possible to exploit this vulnerability by opening a crafted .MP4 file.

CVE-2017-14259 bento4 vulnerability CVSS: 6.8 11 Sep 2017, 09:29 UTC

In the SDK in Bento4 1.5.0-616, the AP4_StscAtom class in Ap4StscAtom.cpp contains a Write Memory Access Violation vulnerability. It is possible to exploit this vulnerability and possibly execute arbitrary code by opening a crafted .MP4 file.

CVE-2017-14258 bento4 vulnerability CVSS: 6.8 11 Sep 2017, 09:29 UTC

In the SDK in Bento4 1.5.0-616, SetItemCount in Core/Ap4StscAtom.h file contains a Write Memory Access Violation vulnerability. It is possible to exploit this vulnerability and possibly execute arbitrary code by opening a crafted .MP4 file.

CVE-2017-14257 bento4 vulnerability CVSS: 6.8 11 Sep 2017, 09:29 UTC

In the SDK in Bento4 1.5.0-616, AP4_AtomSampleTable::GetSample in Core/Ap4AtomSampleTable.cpp contains a Read Memory Access Violation vulnerability. It is possible to exploit this vulnerability by opening a crafted .MP4 file.