📦 Bento4

by Axiosys

🔍 What is Bento4?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-31004

CRITICAL CVSS 9.8 Apr 2, 2024

CVE-2024-31004 is a critical remote code execution vulnerability in Bento4's MP4 fragment parsing functionality. An attacker can exploit this by sending a specially crafted MP4 file to execute arbitra...

CVE-2024-31002

CRITICAL CVSS 9.8 Apr 2, 2024

A buffer overflow vulnerability in Bento4 v1.6.0-641 allows remote attackers to execute arbitrary code via the AP4 BitReader::ReadCache() function. This affects any application using the vulnerable Be...

CVE-2025-25943

HIGH CVSS 7.8 Feb 19, 2025

A buffer overflow vulnerability in Bento4 v1.6.0-641 allows local attackers to execute arbitrary code via the AP4_Stz2Atom component. This affects systems running vulnerable versions of Bento4, partic...

CVE-2025-25944

HIGH CVSS 7.3 Feb 19, 2025

A buffer overflow vulnerability in Bento4 v1.6.0-641 allows local attackers to execute arbitrary code by crafting a malicious MP4 file and processing it with mp4fragment. This affects systems running ...

CVE-2024-30807

HIGH CVSS 7.5 Apr 2, 2024

This vulnerability is a heap-use-after-free flaw in Bento4 v1.6.0-641-2-g1529b83 that occurs during destruction of AP4_UnknownAtom objects. It allows attackers to cause denial of service by crashing a...

CVE-2024-30809

HIGH CVSS 7.5 Apr 2, 2024

A heap-use-after-free vulnerability in Bento4 v1.6.0-641-2-g1529b83 allows attackers to cause denial of service by triggering memory corruption in the AP4_Sample::GetOffset() function. This affects sy...

CVE-2018-10790

HIGH CVSS 7.5 Aug 25, 2021

This vulnerability in Bento4's AP4_CttsAtom class allows remote attackers to cause denial of service through application crashes by triggering memory allocation failures. It affects systems using Bent...

CVE-2020-23330

HIGH CVSS 7.5 Aug 17, 2021

A NULL pointer dereference vulnerability in Bento4's AP4_Stz2Atom::GetSampleSize function allows attackers to cause denial of service by crashing the application. This affects systems using vulnerable...

CVE-2020-23332

HIGH CVSS 7.5 Aug 17, 2021

A heap-based buffer overflow vulnerability exists in Bento4's AP4_StdcFileByteStream::ReadPartial component, allowing attackers to cause denial of service (DoS) by crashing the application. This affec...

CVE-2020-23334

HIGH CVSS 7.5 Aug 17, 2021

This vulnerability in Bento4's AP4_NullTerminatedStringAtom component allows attackers to cause a segmentation fault via improper memory write access. It affects systems using vulnerable versions of B...

CVE-2025-25942

MEDIUM CVSS 6.5 Feb 19, 2025

A memory leak vulnerability in Bento4's mp4fragment tool allows attackers to cause information disclosure by processing specially crafted invalid MP4 files. This affects systems using Bento4 v1.6.0-64...

CVE-2025-25945

MEDIUM CVSS 6.5 Feb 19, 2025

This vulnerability in Bento4 v1.6.0-641 allows attackers to read sensitive information from memory through improper handling of MP4 files. It affects applications using Bento4 for MP4 processing, part...

CVE-2025-25947

MEDIUM CVSS 5.5 Feb 19, 2025

This vulnerability in Bento4 v1.6.0-641 allows attackers to cause a segmentation fault (crash) by providing a specially crafted MP4 file to the mp4encrypt tool. This affects systems using Bento4 for M...

CVE-2025-0753

MEDIUM CVSS 6.3 Jan 27, 2025

A critical heap-based buffer overflow vulnerability in Axiomatic Bento4's mp42aac component allows remote attackers to execute arbitrary code or cause denial of service. This affects all users of Bent...