CVE Tools

Bento4

173 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Bento4, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

Bento4 CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Bento4 CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-013
2025-027
2025-030
2025-040
2025-050
2025-060
2025-070
2025-081
2025-090
2025-100
2025-110
2025-120
2026-010
2026-020
2026-032
2026-040
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 173 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical53%
  • High5733%
  • Medium10963%
  • Low21%

Latest CVEs

The 15 most recently published vulnerabilities affecting Bento4.

  1. CVE-2026-5236Axiomatic Bento4 DSI v1 Ap4Dac4Atom.cpp SkipBits heap-based overflow5.3
  2. CVE-2026-5235Axiomatic Bento4 MP4 File Ap4Dac4Atom.cpp ReadCache heap-based overflow5.3
  3. CVE-2025-8537Axiomatic Bento4 mp4decrypt Mp4Decrypt.cpp SetDataSize allocation of resources3.7
  4. CVE-2025-25946An issue in Bento4 v1.6.0-641 allows an attacker to cause a memory leak via Ap4Marlin.cpp and Ap4Processor.cpp, specifically in AP4_MarlinIpmpEncryptingProcessor::Initialize and AP4_Processor::Proc...5.5
  5. CVE-2025-25947An issue in Bento4 v1.6.0-641 allows an attacker to trigger a segmentation fault via Ap4Atom.cpp, specifically in AP4_AtomParent::RemoveChild, during the execution of mp4encrypt with a specially cr...5.5
  6. CVE-2025-25943Buffer Overflow vulnerability in Bento4 v.1.6.0-641 allows a local attacker to execute arbitrary code via the AP4_Stz2Atom::AP4_Stz2Atom component located in Ap4Stz2Atom.cpp.7.8
  7. CVE-2025-25942An issue in Bento4 v1.6.0-641 allows an attacker to obtain sensitive information via the the mp4fragment tool when processing invalid files. Specifically, memory allocated in SampleArray::SampleArr...6.5
  8. CVE-2025-25945An issue in Bento4 v1.6.0-641 allows an attacker to obtain sensitive information via the the Mp4Fragment.cpp and in AP4_DescriptorFactory::CreateDescriptorFromStream at Ap4DescriptorFactory.cpp.6.5
  9. CVE-2025-25944Buffer Overflow vulnerability in Bento4 v.1.6.0-641 allows a local attacker to execute arbitrary code via the Ap4RtpAtom.cpp, specifically in AP4_RtpAtom::AP4_RtpAtom, during the execution of mp4fr...7.3
  10. CVE-2024-57598A floating point exception (divide-by-zero) vulnerability was discovered in Bento4 1.6.0-641 in function AP4_TfraAtom() of Ap4TfraAtom.cpp which allows a remote attacker to cause a denial of servic...6.5
  11. CVE-2025-0870Axiomatic Bento4 Ap4DataBuffer.h GetData heap-based overflow5.6
  12. CVE-2025-0753Axiomatic Bento4 mp42aac ReadPartial heap-based overflow6.3
  13. CVE-2025-0751Axiomatic Bento4 mp42aac ReadBits heap-based overflow6.3
  14. CVE-2024-31002Buffer Overflow vulnerability in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the AP4 BitReader::ReadCache() at Ap4Utils.cpp component.9.8
  15. CVE-2024-31004An issue in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the Ap4StsdAtom.cpp,AP4_StsdAtom::AP4_StsdAtom,mp4fragment.9.8

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store