AxiosysCVEs & Vulnerabilities

156 CVEs affecting Axiosys products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

bento4 156
CVE-2022-3664HIGH

A vulnerability classified as critical has been found in Axiomatic Bento4. Affected is the function AP4_BitStream::WriteBytes of the file Ap4BitStream.cpp of the component avcinfo. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-212004.

26 Oct 2022
7.8
CVSS
CVE-2022-3663MEDIUM

A vulnerability was found in Axiomatic Bento4. It has been rated as problematic. This issue affects the function AP4_StsdAtom of the file Ap4StsdAtom.cpp of the component MP4fragment. The manipulation leads to null pointer dereference. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-212003.

26 Oct 2022
5.5
CVSS
CVE-2022-3662HIGH

A vulnerability was found in Axiomatic Bento4. It has been declared as critical. This vulnerability affects the function GetOffset of the file Ap4Sample.h of the component mp42hls. The manipulation leads to use after free. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-212002 is the identifier assigned to this vulnerability.

26 Oct 2022
7.8
CVSS
CVE-2022-40885MEDIUM

Bento4 v1.6.0-639 has a memory allocation issue that can cause denial of service.

19 Oct 2022
5.5
CVSS
CVE-2022-40884MEDIUM

Bento4 1.6.0 has memory leaks via the mp4fragment.

19 Oct 2022
5.5
CVSS
CVE-2022-43038MEDIUM

Bento4 v1.6.0-639 was discovered to contain a heap overflow via the AP4_BitReader::ReadCache() function in mp42ts.

19 Oct 2022
6.5
CVSS
CVE-2022-43037MEDIUM

An issue was discovered in Bento4 1.6.0-639. There is a memory leak in the function AP4_File::ParseStream in /Core/Ap4File.cpp.

19 Oct 2022
6.5
CVSS
CVE-2022-43035MEDIUM

An issue was discovered in Bento4 v1.6.0-639. There is a heap-buffer-overflow in AP4_Dec3Atom::AP4_Dec3Atom at Ap4Dec3Atom.cpp, leading to a Denial of Service (DoS), as demonstrated by mp42aac.

19 Oct 2022
6.5
CVSS
CVE-2022-43034MEDIUM

An issue was discovered in Bento4 v1.6.0-639. There is a heap buffer overflow vulnerability in the AP4_BitReader::SkipBits(unsigned int) function in mp42ts.

19 Oct 2022
6.5
CVSS
CVE-2022-43033MEDIUM

An issue was discovered in Bento4 1.6.0-639. There is a bad free in the component AP4_HdlrAtom::~AP4_HdlrAtom() which allows attackers to cause a Denial of Service (DoS) via a crafted input.

19 Oct 2022
6.5
CVSS
CVE-2022-43032MEDIUM

An issue was discovered in Bento4 v1.6.0-639. There is a memory leak in AP4_DescriptorFactory::CreateDescriptorFromStream in Core/Ap4DescriptorFactory.cpp, as demonstrated by mp42aac.

19 Oct 2022
6.5
CVSS
CVE-2022-41430HIGH

Bento4 v1.6.0-639 was discovered to contain a heap overflow via the AP4_BitReader::ReadBit function in mp4mux.

3 Oct 2022
8.8
CVSS
CVE-2022-41429HIGH

Bento4 v1.6.0-639 was discovered to contain a heap overflow via the AP4_Atom::TypeFromString function in mp4tag.

3 Oct 2022
8.8
CVSS
CVE-2022-41428HIGH

Bento4 v1.6.0-639 was discovered to contain a heap overflow via the AP4_BitReader::ReadBits function in mp4mux.

3 Oct 2022
8.8
CVSS
CVE-2022-41427MEDIUM

Bento4 v1.6.0-639 was discovered to contain a memory leak in the AP4_AvcFrameParser::Feed function in mp4mux.

3 Oct 2022
6.5
CVSS
CVE-2022-41426MEDIUM

Bento4 v1.6.0-639 was discovered to contain a memory leak via the AP4_AtomFactory::CreateAtomFromStream function in mp4split.

3 Oct 2022
6.5
CVSS
CVE-2022-41425MEDIUM

Bento4 v1.6.0-639 was discovered to contain a segmentation violation via the AP4_Processor::ProcessFragments function in mp4decrypt.

3 Oct 2022
6.5
CVSS
CVE-2022-41424MEDIUM

Bento4 v1.6.0-639 was discovered to contain a memory leak via the AP4_SttsAtom::Create function in mp42hls.

3 Oct 2022
6.5
CVSS
CVE-2022-41423MEDIUM

Bento4 v1.6.0-639 was discovered to contain a segmentation violation in the mp4fragment component.

3 Oct 2022
6.5
CVSS
CVE-2022-41419MEDIUM

Bento4 v1.6.0-639 was discovered to contain a memory leak via the AP4_Processor::Process function in the mp4encrypt binary.

3 Oct 2022
6.5
CVSS
CVE-2022-41847MEDIUM

An issue was discovered in Bento4 1.6.0-639. A memory leak exists in AP4_StdcFileByteStream::Create(AP4_FileByteStream*, char const*, AP4_FileByteStream::Mode, AP4_ByteStream*&) in System/StdC/Ap4StdCFileByteStream.cpp.

30 Sep 2022
5.5
CVSS
CVE-2022-41846MEDIUM

An issue was discovered in Bento4 1.6.0-639. There ie excessive memory consumption in the function AP4_DataBuffer::ReallocateBuffer in Core/Ap4DataBuffer.cpp.

30 Sep 2022
5.5
CVSS
CVE-2022-41845MEDIUM

An issue was discovered in Bento4 1.6.0-639. There ie excessive memory consumption in the function AP4_Array<AP4_ElstEntry>::EnsureCapacity in Core/Ap4Array.h.

30 Sep 2022
5.5
CVSS
CVE-2022-41841MEDIUM

An issue was discovered in Bento4 through 1.6.0-639. A NULL pointer dereference occurs in AP4_File::ParseStream in Core/Ap4File.cpp, which is called from AP4_File::AP4_File.

30 Sep 2022
5.5
CVSS
CVE-2022-40775MEDIUM

An issue was discovered in Bento4 through 1.6.0-639. A NULL pointer dereference occurs in AP4_StszAtom::WriteFields.

18 Sep 2022
5.5
CVSS
CVE-2022-40774MEDIUM

An issue was discovered in Bento4 through 1.6.0-639. There is a NULL pointer dereference in AP4_StszAtom::GetSampleSize.

18 Sep 2022
5.5
CVSS
CVE-2022-40738MEDIUM

An issue was discovered in Bento4 through 1.6.0-639. A NULL pointer dereference occurs in AP4_DescriptorListWriter::Action in Core/Ap4Descriptor.h, called from AP4_EsDescriptor::WriteFields and AP4_Expandable::Write.

15 Sep 2022
6.5
CVSS
CVE-2022-40737MEDIUM

An issue was discovered in Bento4 through 1.6.0-639. A buffer over-read exists in the function AP4_StdcFileByteStream::WritePartial located in System/StdC/Ap4StdCFileByteStream.cpp, called from AP4_ByteStream::Write and AP4_HdlrAtom::WriteFields.

15 Sep 2022
6.5
CVSS
CVE-2022-40736MEDIUM

An issue was discovered in Bento4 1.6.0-639. There ie excessive memory consumption in AP4_CttsAtom::Create in Core/Ap4CttsAtom.cpp.

15 Sep 2022
6.5
CVSS
CVE-2022-40439MEDIUM

An memory leak issue was discovered in AP4_StdcFileByteStream::Create in mp42ts in Bento4 v1.6.0-639, allows attackers to cause a denial of service via a crafted file.

15 Sep 2022
6.5
CVSS
CVE-2022-40438MEDIUM

Buffer overflow vulnerability in function AP4_MemoryByteStream::WritePartial in mp42aac in Bento4 v1.6.0-639, allows attackers to cause a denial of service via a crafted file.

15 Sep 2022
6.5
CVSS
CVE-2022-35165MEDIUM

An issue in AP4_SgpdAtom::AP4_SgpdAtom() of Bento4-1.6.0-639 allows attackers to cause a Denial of Service (DoS) via a crafted mp4 input.

18 Aug 2022
5.5
CVSS
CVE-2021-40943MEDIUM

In Bento4 1.6.0-638, there is a null pointer reference in the function AP4_DescriptorListInspector::Action function in Ap4Descriptor.h:124 , as demonstrated by GPAC. This can cause a denial of service (DOS).

28 Jun 2022
5.5
CVSS
CVE-2021-40941HIGH

In Bento4 1.6.0-638, there is an allocator is out of memory in the function AP4_Array<AP4_TrunAtom::Entry>::EnsureCapacity in Ap4Array.h:172, as demonstrated by GPAC. This can cause a denial of service (DOS).

27 Jun 2022
7.5
CVSS
CVE-2022-31287MEDIUM

An issue was discovered in Bento4 v1.2. There is an allocation size request error in /Ap4RtpAtom.cpp.

10 Jun 2022
5.5
CVSS
CVE-2022-31285MEDIUM

An issue was discovered in Bento4 1.2. The allocator is out of memory in /Source/C++/Core/Ap4Array.h.

10 Jun 2022
5.5
CVSS
CVE-2022-31282MEDIUM

Bento4 MP4Dump v1.2 was discovered to contain a segmentation violation via an unknown address at /Source/C++/Core/Ap4DataBuffer.cpp:175.

10 Jun 2022
5.5
CVSS
CVE-2022-29017MEDIUM

Bento4 v1.6.0.0 was discovered to contain a segmentation fault via the component /x86_64/multiarch/strlen-avx2.S.

16 May 2022
5.5
CVSS
CVE-2022-27607HIGH

Bento4 1.6.0-639 has a heap-based buffer over-read in the AP4_HvccAtom class, a different issue than CVE-2018-14531.

22 Mar 2022
8.1
CVSS
CVE-2021-32265HIGH

An issue was discovered in Bento4 through v1.6.0-637. A global-buffer-overflow exists in the function AP4_MemoryByteStream::WritePartial() located in Ap4ByteStream.cpp. It allows an attacker to cause code execution or information disclosure.

20 Sep 2021
8.8
CVSS
CVE-2018-10790HIGH

The AP4_CttsAtom class in Core/Ap4CttsAtom.cpp in Bento4 1.5.1.0 allows remote attackers to cause a denial of service (application crash), related to a memory allocation failure, as demonstrated by mp2aac.

25 Aug 2021
7.5
CVSS
CVE-2020-23334HIGH

A WRITE memory access in the AP4_NullTerminatedStringAtom::AP4_NullTerminatedStringAtom component of Bento4 version 06c39d9 can lead to a segmentation fault.

18 Aug 2021
7.5
CVSS
CVE-2020-23333HIGH

A heap-based buffer overflow exists in the AP4_CttsAtom::AP4_CttsAtom component located in /Core/Ap4Utils.h of Bento4 version 06c39d9. This can lead to a denial of service (DOS).

18 Aug 2021
7.5
CVSS
CVE-2020-23332HIGH

A heap-based buffer overflow exists in the AP4_StdcFileByteStream::ReadPartial component located in /StdC/Ap4StdCFileByteStream.cpp of Bento4 version 06c39d9. This issue can lead to a denial of service (DOS).

18 Aug 2021
7.5
CVSS
CVE-2020-23331HIGH

An issue was discovered in Bento4 version 06c39d9. A NULL pointer dereference exists in the AP4_DescriptorListWriter::Action component located in /Core/Ap4Descriptor.h. It allows an attacker to cause a denial of service (DOS).

18 Aug 2021
7.5
CVSS
CVE-2020-23330HIGH

An issue was discovered in Bento4 version 06c39d9. A NULL pointer dereference exists in the AP4_Stz2Atom::GetSampleSize component located in /Core/Ap4Stz2Atom.cpp. It allows an attacker to cause a denial of service (DOS).

18 Aug 2021
7.5
CVSS
CVE-2020-21066MEDIUM

An issue was discovered in Bento4 v1.5.1.0. There is a heap-buffer-overflow in AP4_Dec3Atom::AP4_Dec3Atom at Ap4Dec3Atom.cpp, leading to a denial of service (program crash), as demonstrated by mp42aac.

14 Aug 2021
6.5
CVSS
CVE-2021-35307MEDIUM

An issue was discovered in Bento4 through v1.6.0-636. A NULL pointer dereference exists in the AP4_DescriptorFinder::Test component located in /Core/Ap4Descriptor.h. It allows an attacker to cause a denial of service (DOS).

5 Aug 2021
6.5
CVSS
Axiosys CVEs & Vulnerabilities — 156 Tracked — Page 2