CVE Tools

Bento4

15 CVEs tracked since 2017. Since Sep 2017, none of them reached CISA KEV.

Bento4 CVEs per month

Sep 2017 to Sep 2017. Point at a month, or focus the strip and use the arrow keys.
Bento4 CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2017-09150

Products

The products that kept showing up in Bento4's monthly top three, with their CVEs summed over those months.

  1. Bento4151 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Bento4.

  1. CVE-2017-14642A NULL pointer dereference was discovered in the AP4_HdlrAtom class in Bento4 version 1.5.0-617. The vulnerability causes a segmentation fault and application crash in AP4_StdcFileByteStream::ReadP...6.5
  2. CVE-2017-14647A heap-based buffer overflow was discovered in AP4_VisualSampleEntry::ReadFields in Core/Ap4SampleEntry.cpp in Bento4 1.5.0-617. The vulnerability causes an out-of-bounds write, which leads to remo...8.8
  3. CVE-2017-14645A heap-based buffer over-read was discovered in AP4_BitStream::ReadBytes in Codecs/Ap4BitStream.cpp in Bento4 version 1.5.0-617. The vulnerability causes an application crash, which leads to remote...6.5
  4. CVE-2017-14639AP4_VisualSampleEntry::ReadFields in Core/Ap4SampleEntry.cpp in Bento4 1.5.0-617 uses incorrect character data types, which causes a stack-based buffer underflow and out-of-bounds write, leading to...8.8
  5. CVE-2017-14638AP4_AtomFactory::CreateAtomFromStream in Core/Ap4AtomFactory.cpp in Bento4 version 1.5.0-617 has missing NULL checks, leading to a NULL pointer dereference, segmentation fault, and application cras...6.5
  6. CVE-2017-14641A NULL pointer dereference was discovered in the AP4_DataAtom class in MetaData/Ap4MetaData.cpp in Bento4 version 1.5.0-617. The vulnerability causes a segmentation fault and application crash, whi...6.5
  7. CVE-2017-14640A NULL pointer dereference was discovered in AP4_AtomSampleTable::GetSample in Core/Ap4AtomSampleTable.cpp in Bento4 version 1.5.0-617. The vulnerability causes a segmentation fault and application...6.5
  8. CVE-2017-14644A heap-based buffer overflow was discovered in the AP4_HdlrAtom class in Bento4 1.5.0-617. The vulnerability causes an out-of-bounds write, which leads to remote denial of service or possibly code ...8.8
  9. CVE-2017-14643The AP4_HdlrAtom class in Core/Ap4HdlrAtom.cpp in Bento4 version 1.5.0-617 uses an incorrect character data type, leading to a heap-based buffer over-read and application crash in AP4_BytesToUInt32...6.5
  10. CVE-2017-14258In the SDK in Bento4 1.5.0-616, SetItemCount in Core/Ap4StscAtom.h file contains a Write Memory Access Violation vulnerability. It is possible to exploit this vulnerability and possibly execute arb...7.8
  11. CVE-2017-14259In the SDK in Bento4 1.5.0-616, the AP4_StscAtom class in Ap4StscAtom.cpp contains a Write Memory Access Violation vulnerability. It is possible to exploit this vulnerability and possibly execute a...7.8
  12. CVE-2017-14257In the SDK in Bento4 1.5.0-616, AP4_AtomSampleTable::GetSample in Core/Ap4AtomSampleTable.cpp contains a Read Memory Access Violation vulnerability. It is possible to exploit this vulnerability by ...7.8
  13. CVE-2017-14261In the SDK in Bento4 1.5.0-616, the AP4_StszAtom class in Ap4StszAtom.cpp file contains a Read Memory Access Violation vulnerability. It is possible to exploit this vulnerability by opening a craft...7.8
  14. CVE-2017-12476The AP4_AvccAtom::InspectFields function in Core/Ap4AvccAtom.cpp in Bento4 mp4dump before 1.5.0-616 allows remote attackers to cause a denial of service (NULL pointer dereference and application cr...5.5
  15. CVE-2017-12474The AP4_AtomSampleTable::GetSample function in Core/Ap4AtomSampleTable.cpp in Bento4 mp42ts before 1.5.0-616 allows remote attackers to cause a denial of service (NULL pointer dereference and appli...5.5

The record

Peak rank
#25 in Sep 2017
Busiest month shown
Sep 2017, 15 CVEs
Months with a KEV entry
0 since Sep 2017
Monthly snapshots
1 since 2017
Bento4's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store