CVE-2025-0751
- EPSS 0.13%
- Veröffentlicht 27.01.2025 20:15:34
- Zuletzt bearbeitet 28.02.2025 22:16:37
A vulnerability classified as critical has been found in Axiomatic Bento4 up to 1.6.0. This affects the function AP4_BitReader::ReadBits of the component mp42aac. The manipulation leads to heap-based buffer overflow. It is possible to initiate the at...
CVE-2024-30806
- EPSS 0.15%
- Veröffentlicht 02.04.2024 18:15:12
- Zuletzt bearbeitet 27.05.2025 13:49:26
An issue was discovered in Bento4 v1.6.0-641-2-g1529b83. There is a heap overflow in AP4_Dec3Atom::AP4_Dec3Atom at Ap4Dec3Atom.cpp, leading to a Denial of Service (DoS), as demonstrated by mp42aac.
CVE-2024-30807
- EPSS 0.08%
- Veröffentlicht 02.04.2024 18:15:12
- Zuletzt bearbeitet 27.05.2025 13:55:30
An issue was discovered in Bento4 v1.6.0-641-2-g1529b83. There is a heap-use-after-free in AP4_UnknownAtom::~AP4_UnknownAtom at Ap4Atom.cpp, leading to a Denial of Service (DoS), as demonstrated by mp42ts.
CVE-2024-30808
- EPSS 0.04%
- Veröffentlicht 02.04.2024 18:15:12
- Zuletzt bearbeitet 27.05.2025 13:59:21
An issue was discovered in Bento4 v1.6.0-641-2-g1529b83. There is a heap-use-after-free in AP4_SubStream::~AP4_SubStream at Ap4ByteStream.cpp, leading to a Denial of Service (DoS), as demonstrated by mp42ts.
CVE-2024-30809
- EPSS 0.08%
- Veröffentlicht 02.04.2024 18:15:12
- Zuletzt bearbeitet 27.05.2025 14:00:22
An issue was discovered in Bento4 v1.6.0-641-2-g1529b83. There is a heap-use-after-free in Ap4Sample.h in AP4_Sample::GetOffset() const, leading to a Denial of Service (DoS), as demonstrated by mp42ts.
CVE-2024-31005
- EPSS 9.6%
- Veröffentlicht 02.04.2024 08:16:16
- Zuletzt bearbeitet 07.05.2025 00:20:26
An issue in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the Ap4MdhdAtom.cpp,AP4_MdhdAtom::AP4_MdhdAtom,mp4fragment
CVE-2024-31004
- EPSS 7.41%
- Veröffentlicht 02.04.2024 08:16:10
- Zuletzt bearbeitet 27.03.2025 17:15:55
An issue in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the Ap4StsdAtom.cpp,AP4_StsdAtom::AP4_StsdAtom,mp4fragment.
CVE-2024-31003
- EPSS 8.95%
- Veröffentlicht 02.04.2024 08:16:05
- Zuletzt bearbeitet 07.05.2025 00:23:38
Buffer Overflow vulnerability in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the AP4_MemoryByteStream::WritePartial at Ap4ByteStream.cpp.
CVE-2024-31002
- EPSS 8.23%
- Veröffentlicht 02.04.2024 08:15:59
- Zuletzt bearbeitet 07.05.2025 00:24:41
Buffer Overflow vulnerability in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the AP4 BitReader::ReadCache() at Ap4Utils.cpp component.
CVE-2024-24155
- EPSS 0.2%
- Veröffentlicht 29.02.2024 01:44:11
- Zuletzt bearbeitet 16.01.2025 17:51:56
Bento4 v1.5.1-628 contains a Memory leak on AP4_Movie::AP4_Movie, parsing tracks and added into m_Tracks list, but mp42aac cannot correctly delete when we got an no audio track found error. This vulnerability allows attackers to cause a Denial of Ser...