CVE-2026-88377
- EPSS 0.15%
- Veröffentlicht 24.09.2026 00:00:00
- Zuletzt bearbeitet 29.09.2026 03:17:20
Bento4 1.6.0.0 contains an integer underflow vulnerability in the avcC and hvcC configuration atom parsers. A specially crafted MP4 file containing an atom with a declared size smaller than AP4_ATOM_HEADER_SIZE can cause AP4_AvccAtom::Create() or AP4...
CVE-2026-88376
- EPSS 0.39%
- Veröffentlicht 24.09.2026 00:00:00
- Zuletzt bearbeitet 24.09.2026 21:08:55
Bento4 1.6.0.0 contains an integer underflow vulnerability in AP4_AvccAtom::Create() and AP4_HvccAtom::Create(). A specially crafted MP4 file containing an avcC or hvcC atom with a declared size smaller than the atom header size can cause the payload...
CVE-2025-25947
- EPSS 0.21%
- Veröffentlicht 19.02.2025 23:15:15
- Zuletzt bearbeitet 13.05.2025 14:02:23
An issue in Bento4 v1.6.0-641 allows an attacker to trigger a segmentation fault via Ap4Atom.cpp, specifically in AP4_AtomParent::RemoveChild, during the execution of mp4encrypt with a specially crafted MP4 input file.
CVE-2025-25946
- EPSS 0.21%
- Veröffentlicht 19.02.2025 23:15:15
- Zuletzt bearbeitet 09.06.2025 16:49:57
An issue in Bento4 v1.6.0-641 allows an attacker to cause a memory leak via Ap4Marlin.cpp and Ap4Processor.cpp, specifically in AP4_MarlinIpmpEncryptingProcessor::Initialize and AP4_Processor::Process, during the execution of mp4encrypt with a specia...
CVE-2025-25945
- EPSS 0.37%
- Veröffentlicht 19.02.2025 23:15:15
- Zuletzt bearbeitet 13.05.2025 14:02:19
An issue in Bento4 v1.6.0-641 allows an attacker to obtain sensitive information via the the Mp4Fragment.cpp and in AP4_DescriptorFactory::CreateDescriptorFromStream at Ap4DescriptorFactory.cpp.
CVE-2025-25944
- EPSS 0.24%
- Veröffentlicht 19.02.2025 23:15:15
- Zuletzt bearbeitet 13.05.2025 14:02:17
Buffer Overflow vulnerability in Bento4 v.1.6.0-641 allows a local attacker to execute arbitrary code via the Ap4RtpAtom.cpp, specifically in AP4_RtpAtom::AP4_RtpAtom, during the execution of mp4fragment with a crafted MP4 input file.
CVE-2025-25943
- EPSS 0.23%
- Veröffentlicht 19.02.2025 23:15:15
- Zuletzt bearbeitet 13.05.2025 14:02:15
Buffer Overflow vulnerability in Bento4 v.1.6.0-641 allows a local attacker to execute arbitrary code via the AP4_Stz2Atom::AP4_Stz2Atom component located in Ap4Stz2Atom.cpp.
CVE-2025-25942
- EPSS 0.37%
- Veröffentlicht 19.02.2025 23:15:15
- Zuletzt bearbeitet 13.05.2025 14:02:13
An issue in Bento4 v1.6.0-641 allows an attacker to obtain sensitive information via the the mp4fragment tool when processing invalid files. Specifically, memory allocated in SampleArray::SampleArray in Mp4Fragment.cpp is not properly released.
CVE-2024-57598
- EPSS 0.44%
- Veröffentlicht 05.02.2025 22:15:33
- Zuletzt bearbeitet 05.07.2026 01:21:21
A floating point exception (divide-by-zero) vulnerability was discovered in Bento4 1.6.0-641 in function AP4_TfraAtom() of Ap4TfraAtom.cpp which allows a remote attacker to cause a denial of service vulnerability.
CVE-2024-57513
- EPSS 0.31%
- Veröffentlicht 29.01.2025 22:15:30
- Zuletzt bearbeitet 15.04.2026 00:35:42
A floating-point exception (FPE) vulnerability exists in the AP4_TfraAtom::AP4_TfraAtom function in Bento4.