Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 166 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
180 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.2) | 0.12% | — | Bento4AI | 24/9/2026 | 29/9/2026 | Bento4 1.6.0.0 contains an integer underflow vulnerability in the avcC and hvcC configuration atom parsers. A specially crafted MP4 file containing an atom with a declared size smaller than AP4_ATOM_HEADER_SIZE can cause AP4_AvccAtom::Create() or AP4_HvccAtom::Create() to underflow the payload-size calculation. The… | |
| Aplazada | Alta (7.5) | 0.39% | — | Bento4AI | 24/9/2026 | 24/9/2026 | Bento4 1.6.0.0 contains an integer underflow vulnerability in AP4_AvccAtom::Create() and AP4_HvccAtom::Create(). A specially crafted MP4 file containing an avcC or hvcC atom with a declared size smaller than the atom header size can cause the payload-size calculation to wrap to a large unsigned value. The resulting… | |
| Aplazada | Media (5.5) | 0.18% | — | Axiomatic Systems Bento4AI | 26/6/2026 | 29/6/2026 | A stack overflow in the AP4_Array<AP4_TrunAtom::Entry>::EnsureCapacity component of axiomatic-systems Bento4 before v1.8.9allows attackers to cause a Denial of Service (DoS) via a crafted MP4 file. | |
| Aplazada | Media (5.5) | 0.16% | — | Axiomatic Systems Bento4AI | 26/6/2026 | 29/6/2026 | A stack overflow in the AP4_StsdAtom::AP4_StsdAtom component of axiomatic-systems Bento4 before v1.8.9allows attackers to cause a Denial of Service (DoS) via a crafted MP4 file. | |
| Aplazada | Baja (1.9) | 0.17% | — | Axiomatic Bento4AI | 31/3/2026 | 17/6/2026 | A vulnerability was identified in Axiomatic Bento4 up to 1.6.0-641. Affected is the function AP4_BitReader::SkipBits of the file Ap4Dac4Atom.cpp of the component DSI v1 Parser. Such manipulation of the argument n_presentations leads to heap-based buffer overflow. The attack needs to be performed locally. The exploit… | |
| Aplazada | Baja (1.9) | 0.17% | — | Axiomatic Bento4AI | 31/3/2026 | 17/6/2026 | A vulnerability was determined in Axiomatic Bento4 up to 1.6.0-641. This impacts the function AP4_BitReader::ReadCache of the file Ap4Dac4Atom.cpp of the component MP4 File Parser. This manipulation causes heap-based buffer overflow. The attack needs to be launched locally. The exploit has been publicly disclosed and… | |
| Analizada | Baja (2.9) | 0.62% | — | Axiosys Bento4 | 5/8/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in Axiomatic Bento4 up to 1.6.0-641. Affected is the function AP4_DataBuffer::SetDataSize of the file Mp4Decrypt.cpp of the component mp4decrypt. The manipulation leads to allocation of resources. It is possible to launch the attack remotely. The… | |
| Analizada | Media (5.5) | 0.21% | — | Axiosys Bento4 | 19/2/2025 | 17/6/2026 | An issue in Bento4 v1.6.0-641 allows an attacker to trigger a segmentation fault via Ap4Atom.cpp, specifically in AP4_AtomParent::RemoveChild, during the execution of mp4encrypt with a specially crafted MP4 input file. | |
| Analizada | Media (5.5) | 0.21% | — | Axiosys Bento4 | 19/2/2025 | 17/6/2026 | An issue in Bento4 v1.6.0-641 allows an attacker to cause a memory leak via Ap4Marlin.cpp and Ap4Processor.cpp, specifically in AP4_MarlinIpmpEncryptingProcessor::Initialize and AP4_Processor::Process, during the execution of mp4encrypt with a specially crafted MP4 input file. | |
| Analizada | Media (6.5) | 0.38% | — | Axiosys Bento4 | 19/2/2025 | 17/6/2026 | An issue in Bento4 v1.6.0-641 allows an attacker to obtain sensitive information via the the Mp4Fragment.cpp and in AP4_DescriptorFactory::CreateDescriptorFromStream at Ap4DescriptorFactory.cpp. | |
| Analizada | Alta (7.3) | 0.24% | — | Axiosys Bento4 | 19/2/2025 | 17/6/2026 | Buffer Overflow vulnerability in Bento4 v.1.6.0-641 allows a local attacker to execute arbitrary code via the Ap4RtpAtom.cpp, specifically in AP4_RtpAtom::AP4_RtpAtom, during the execution of mp4fragment with a crafted MP4 input file. | |
| Analizada | Alta (7.8) | 0.23% | — | Axiosys Bento4 | 19/2/2025 | 17/6/2026 | Buffer Overflow vulnerability in Bento4 v.1.6.0-641 allows a local attacker to execute arbitrary code via the AP4_Stz2Atom::AP4_Stz2Atom component located in Ap4Stz2Atom.cpp. | |
| Analizada | Media (6.5) | 0.38% | — | Axiosys Bento4 | 19/2/2025 | 17/6/2026 | An issue in Bento4 v1.6.0-641 allows an attacker to obtain sensitive information via the the mp4fragment tool when processing invalid files. Specifically, memory allocated in SampleArray::SampleArray in Mp4Fragment.cpp is not properly released. | |
| Modificada | Media (6.5) | 0.45% | — | Axiosys Bento4 | 5/2/2025 | 5/7/2026 | A floating point exception (divide-by-zero) vulnerability was discovered in Bento4 1.6.0-641 in function AP4_TfraAtom() of Ap4TfraAtom.cpp which allows a remote attacker to cause a denial of service vulnerability. | |
| Analizada | Media (6.3) | 0.54% | — | Axiosys Bento4 | 30/1/2025 | 17/6/2026 | A vulnerability was found in Axiomatic Bento4 up to 1.6.0-641. It has been rated as critical. Affected by this issue is the function AP4_DataBuffer::GetData in the library Ap4DataBuffer.h. The manipulation leads to heap-based buffer overflow. The attack may be launched remotely. The complexity of an attack is rather… | |
| Aplazada | Media (6.5) | 0.31% | — | Bento4AI | 29/1/2025 | 17/6/2026 | A floating-point exception (FPE) vulnerability exists in the AP4_TfraAtom::AP4_TfraAtom function in Bento4. | |
| Aplazada | Alta (7.8) | 0.19% | — | Bento4 Mp42avcAI | 29/1/2025 | 17/6/2026 | Buffer Overflow vulnerability in Bento4 mp42avc v.3bdc891602d19789b8e8626e4a3e613a937b4d35 allows a local attacker to execute arbitrary code via the AP4_MemoryByteStream::WritePartial. | |
| Aplazada | Alta (7.8) | 0.19% | — | Bento4 Mp42avcAI | 29/1/2025 | 17/6/2026 | Buffer Overflow vulnerability in Bento4 mp42avc v.3bdc891602d19789b8e8626e4a3e613a937b4d35 allows a local attacker to execute arbitrary code via the AP4_File::ParseStream and related functions. | |
| Analizada | Media (6.9) | 0.45% | — | Axiosys Bento4 | 27/1/2025 | 17/6/2026 | A vulnerability classified as critical was found in Axiomatic Bento4 up to 1.6.0. This vulnerability affects the function AP4_StdcFileByteStream::ReadPartial of the component mp42aac. The manipulation leads to heap-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the… | |
| Analizada | Media (6.9) | 0.49% | — | Axiosys Bento4 | 27/1/2025 | 17/6/2026 | A vulnerability classified as critical has been found in Axiomatic Bento4 up to 1.6.0. This affects the function AP4_BitReader::ReadBits of the component mp42aac. The manipulation leads to heap-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may… | |
| Analizada | Alta (7.5) | 0.67% | — | Axiosys Bento4 | 2/4/2024 | 17/6/2026 | An issue was discovered in Bento4 v1.6.0-641-2-g1529b83. There is a heap-use-after-free in Ap4Sample.h in AP4_Sample::GetOffset() const, leading to a Denial of Service (DoS), as demonstrated by mp42ts. | |
| Analizada | Baja (2.7) | 0.57% | — | Axiosys Bento4 | 2/4/2024 | 17/6/2026 | An issue was discovered in Bento4 v1.6.0-641-2-g1529b83. There is a heap-use-after-free in AP4_SubStream::~AP4_SubStream at Ap4ByteStream.cpp, leading to a Denial of Service (DoS), as demonstrated by mp42ts. | |
| Analizada | Alta (7.5) | 0.67% | — | Axiosys Bento4 | 2/4/2024 | 17/6/2026 | An issue was discovered in Bento4 v1.6.0-641-2-g1529b83. There is a heap-use-after-free in AP4_UnknownAtom::~AP4_UnknownAtom at Ap4Atom.cpp, leading to a Denial of Service (DoS), as demonstrated by mp42ts. | |
| Analizada | Media (6.5) | 0.53% | — | Axiosys Bento4 | 2/4/2024 | 17/6/2026 | An issue was discovered in Bento4 v1.6.0-641-2-g1529b83. There is a heap overflow in AP4_Dec3Atom::AP4_Dec3Atom at Ap4Dec3Atom.cpp, leading to a Denial of Service (DoS), as demonstrated by mp42aac. | |
| Analizada | Alta (8.1) | 1.2% | — | Axiosys Bento4 | 2/4/2024 | 17/6/2026 | An issue in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the Ap4MdhdAtom.cpp,AP4_MdhdAtom::AP4_MdhdAtom,mp4fragment |