Axiosys
Axiosys Bento4: vulnerabilidades y CVE
Axiosys Bento4 tiene 156 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 5 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE156
Últimos 12 meses0
Críticas5
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-8537 | Baja (2.9) | 0.60% | — | 5 ago 2025 | A vulnerability, which was classified as problematic, was found in Axiomatic Bento4 up to 1.6.0-641. Affected is the function AP4_DataBuffer::SetDataSize of the file Mp4Decrypt.cpp of the component mp4decrypt. The… |
| CVE-2025-25947 | Media (5.5) | 0.21% | — | 19 feb 2025 | An issue in Bento4 v1.6.0-641 allows an attacker to trigger a segmentation fault via Ap4Atom.cpp, specifically in AP4_AtomParent::RemoveChild, during the execution of mp4encrypt with a specially crafted MP4 input file. |
| CVE-2025-25946 | Media (5.5) | 0.21% | — | 19 feb 2025 | An issue in Bento4 v1.6.0-641 allows an attacker to cause a memory leak via Ap4Marlin.cpp and Ap4Processor.cpp, specifically in AP4_MarlinIpmpEncryptingProcessor::Initialize and AP4_Processor::Process, during the… |
| CVE-2025-25945 | Media (6.5) | 0.38% | — | 19 feb 2025 | An issue in Bento4 v1.6.0-641 allows an attacker to obtain sensitive information via the the Mp4Fragment.cpp and in AP4_DescriptorFactory::CreateDescriptorFromStream at Ap4DescriptorFactory.cpp. |
| CVE-2025-25944 | Alta (7.3) | 0.24% | — | 19 feb 2025 | Buffer Overflow vulnerability in Bento4 v.1.6.0-641 allows a local attacker to execute arbitrary code via the Ap4RtpAtom.cpp, specifically in AP4_RtpAtom::AP4_RtpAtom, during the execution of mp4fragment with a crafted… |
| CVE-2025-25943 | Alta (7.8) | 0.23% | — | 19 feb 2025 | Buffer Overflow vulnerability in Bento4 v.1.6.0-641 allows a local attacker to execute arbitrary code via the AP4_Stz2Atom::AP4_Stz2Atom component located in Ap4Stz2Atom.cpp. |
| CVE-2025-25942 | Media (6.5) | 0.38% | — | 19 feb 2025 | An issue in Bento4 v1.6.0-641 allows an attacker to obtain sensitive information via the the mp4fragment tool when processing invalid files. Specifically, memory allocated in SampleArray::SampleArray in Mp4Fragment.cpp… |
| CVE-2024-57598 | Media (6.5) | 0.45% | — | 5 feb 2025 | A floating point exception (divide-by-zero) vulnerability was discovered in Bento4 1.6.0-641 in function AP4_TfraAtom() of Ap4TfraAtom.cpp which allows a remote attacker to cause a denial of service vulnerability. |
| CVE-2025-0870 | Media (6.3) | 0.54% | — | 30 ene 2025 | A vulnerability was found in Axiomatic Bento4 up to 1.6.0-641. It has been rated as critical. Affected by this issue is the function AP4_DataBuffer::GetData in the library Ap4DataBuffer.h. The manipulation leads to… |
| CVE-2025-0753 | Media (6.9) | 0.45% | — | 27 ene 2025 | A vulnerability classified as critical was found in Axiomatic Bento4 up to 1.6.0. This vulnerability affects the function AP4_StdcFileByteStream::ReadPartial of the component mp42aac. The manipulation leads to… |
| CVE-2025-0751 | Media (6.9) | 0.49% | — | 27 ene 2025 | A vulnerability classified as critical has been found in Axiomatic Bento4 up to 1.6.0. This affects the function AP4_BitReader::ReadBits of the component mp42aac. The manipulation leads to heap-based buffer overflow. It… |
| CVE-2024-30809 | Alta (7.5) | 0.67% | — | 2 abr 2024 | An issue was discovered in Bento4 v1.6.0-641-2-g1529b83. There is a heap-use-after-free in Ap4Sample.h in AP4_Sample::GetOffset() const, leading to a Denial of Service (DoS), as demonstrated by mp42ts. |
| CVE-2024-30808 | Baja (2.7) | 0.57% | — | 2 abr 2024 | An issue was discovered in Bento4 v1.6.0-641-2-g1529b83. There is a heap-use-after-free in AP4_SubStream::~AP4_SubStream at Ap4ByteStream.cpp, leading to a Denial of Service (DoS), as demonstrated by mp42ts. |
| CVE-2024-30807 | Alta (7.5) | 0.67% | — | 2 abr 2024 | An issue was discovered in Bento4 v1.6.0-641-2-g1529b83. There is a heap-use-after-free in AP4_UnknownAtom::~AP4_UnknownAtom at Ap4Atom.cpp, leading to a Denial of Service (DoS), as demonstrated by mp42ts. |
| CVE-2024-30806 | Media (6.5) | 0.53% | — | 2 abr 2024 | An issue was discovered in Bento4 v1.6.0-641-2-g1529b83. There is a heap overflow in AP4_Dec3Atom::AP4_Dec3Atom at Ap4Dec3Atom.cpp, leading to a Denial of Service (DoS), as demonstrated by mp42aac. |
| CVE-2024-31005 | Alta (8.1) | 1.2% | — | 2 abr 2024 | An issue in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the Ap4MdhdAtom.cpp,AP4_MdhdAtom::AP4_MdhdAtom,mp4fragment |
| CVE-2024-31004 | Crítica (9.8) | 1.5% | — | 2 abr 2024 | An issue in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the Ap4StsdAtom.cpp,AP4_StsdAtom::AP4_StsdAtom,mp4fragment. |
| CVE-2024-31003 | Alta (8.8) | 1.5% | — | 2 abr 2024 | Buffer Overflow vulnerability in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the AP4_MemoryByteStream::WritePartial at Ap4ByteStream.cpp. |
| CVE-2024-31002 | Crítica (9.8) | 1.4% | — | 2 abr 2024 | Buffer Overflow vulnerability in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the AP4 BitReader::ReadCache() at Ap4Utils.cpp component. |
| CVE-2024-24155 | Media (6.5) | 0.64% | — | 29 feb 2024 | Bento4 v1.5.1-628 contains a Memory leak on AP4_Movie::AP4_Movie, parsing tracks and added into m_Tracks list, but mp42aac cannot correctly delete when we got an no audio track found error. This vulnerability allows… |
| CVE-2024-25454 | Media (5.5) | 0.25% | — | 9 feb 2024 | Bento4 v1.6.0-640 was discovered to contain a NULL pointer dereference via the AP4_DescriptorFinder::Test() function. |
| CVE-2024-25453 | Media (5.5) | 0.26% | — | 9 feb 2024 | Bento4 v1.6.0-640 was discovered to contain a NULL pointer dereference via the AP4_StszAtom::GetSampleSize() function. |
| CVE-2024-25452 | Media (5.5) | 0.25% | — | 9 feb 2024 | Bento4 v1.6.0-640 was discovered to contain an out-of-memory bug via the AP4_UrlAtom::AP4_UrlAtom() function. |
| CVE-2024-25451 | Media (6.5) | 0.51% | — | 9 feb 2024 | Bento4 v1.6.0-640 was discovered to contain an out-of-memory bug via the AP4_DataBuffer::ReallocateBuffer() function. |
| CVE-2023-38666 | Media (5.5) | 0.28% | — | 22 ago 2023 | Bento4 v1.6.0-639 was discovered to contain a segmentation violation via the AP4_Processor::ProcessFragments function in mp4encrypt. |
| CVE-2023-29575 | Media (5.5) | 0.31% | — | 21 abr 2023 | Bento4 v1.6.0-639 was discovered to contain an out-of-memory bug in the mp42aac component. |
| CVE-2023-29573 | Media (5.5) | 0.30% | — | 13 abr 2023 | Bento4 v1.6.0-639 was discovered to contain an out-of-memory bug in the mp4info component. |
| CVE-2023-29574 | Media (5.5) | 0.29% | — | 12 abr 2023 | Bento4 v1.6.0-639 was discovered to contain an out-of-memory bug in the mp42avc component. |
| CVE-2023-29576 | Media (5.5) | 0.29% | — | 11 abr 2023 | Bento4 v1.6.0-639 was discovered to contain a segmentation violation via the AP4_TrunAtom::SetDataOffset(int) function in Ap4TrunAtom.h. |
| CVE-2022-4584 | Alta (8.8) | 1.1% | — | 17 dic 2022 | A vulnerability was found in Axiomatic Bento4 up to 1.6.0-639. It has been rated as critical. Affected by this issue is some unknown functionality of the component mp42aac. The manipulation leads to heap-based buffer… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.