Skip to main content

Vendor archive

axiosys CVEs

Beta · best-effort

156 CVEs tagged to vendor axiosys5 Critical, 50 High, 99 Medium, 2 Low, 0 Unrated.

CVE-2025-8537

Published Aug 5, 2025

A vulnerability, which was classified as problematic, was found in Axiomatic Bento4 up to 1.6.0-641. Affected is the function AP4_DataBuffer::SetDataSize of the file Mp4Decrypt.cp…

CVSS 2.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-25947

Published Feb 19, 2025

An issue in Bento4 v1.6.0-641 allows an attacker to trigger a segmentation fault via Ap4Atom.cpp, specifically in AP4_AtomParent::RemoveChild, during the execution of mp4encrypt w…

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
16.4
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-25946

Published Feb 19, 2025

An issue in Bento4 v1.6.0-641 allows an attacker to cause a memory leak via Ap4Marlin.cpp and Ap4Processor.cpp, specifically in AP4_MarlinIpmpEncryptingProcessor::Initialize and A…

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
16.4
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-25945

Published Feb 19, 2025

An issue in Bento4 v1.6.0-641 allows an attacker to obtain sensitive information via the the Mp4Fragment.cpp and in AP4_DescriptorFactory::CreateDescriptorFromStream at Ap4Descrip…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
16.4
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-25944

Published Feb 19, 2025

Buffer Overflow vulnerability in Bento4 v.1.6.0-641 allows a local attacker to execute arbitrary code via the Ap4RtpAtom.cpp, specifically in AP4_RtpAtom::AP4_RtpAtom, during the…

CVSS 7.3 · High
evidence mentions
1
Buzz score
16.4
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-25943

Published Feb 19, 2025

Buffer Overflow vulnerability in Bento4 v.1.6.0-641 allows a local attacker to execute arbitrary code via the AP4_Stz2Atom::AP4_Stz2Atom component located in Ap4Stz2Atom.cpp.

CVSS 7.8 · High
evidence mentions
1
Buzz score
16.4
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-25942

Published Feb 19, 2025

An issue in Bento4 v1.6.0-641 allows an attacker to obtain sensitive information via the the mp4fragment tool when processing invalid files. Specifically, memory allocated in Samp…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
16.4
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2024-57598

Published Feb 5, 2025

A floating point exception (divide-by-zero) vulnerability was discovered in Bento4 1.6.0-641 in function AP4_TfraAtom() of Ap4TfraAtom.cpp which allows a remote attacker to cause…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-0870

Published Jan 30, 2025

A vulnerability was found in Axiomatic Bento4 up to 1.6.0-641. It has been rated as critical. Affected by this issue is the function AP4_DataBuffer::GetData in the library Ap4Data…

CVSS 6.3 · Medium
evidence mentions
4
Buzz score
31.6
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-0753

Published Jan 27, 2025

A vulnerability classified as critical was found in Axiomatic Bento4 up to 1.6.0. This vulnerability affects the function AP4_StdcFileByteStream::ReadPartial of the component mp42…

CVSS 6.9 · Medium
evidence mentions
5
Buzz score
33.4
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-0751

Published Jan 27, 2025

A vulnerability classified as critical has been found in Axiomatic Bento4 up to 1.6.0. This affects the function AP4_BitReader::ReadBits of the component mp42aac. The manipulation…

CVSS 6.9 · Medium
evidence mentions
5
Buzz score
33.4
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2024-30809

Published Apr 2, 2024

An issue was discovered in Bento4 v1.6.0-641-2-g1529b83. There is a heap-use-after-free in Ap4Sample.h in AP4_Sample::GetOffset() const, leading to a Denial of Service (DoS), as d…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-30808

Published Apr 2, 2024

An issue was discovered in Bento4 v1.6.0-641-2-g1529b83. There is a heap-use-after-free in AP4_SubStream::~AP4_SubStream at Ap4ByteStream.cpp, leading to a Denial of Service (DoS)…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-30807

Published Apr 2, 2024

An issue was discovered in Bento4 v1.6.0-641-2-g1529b83. There is a heap-use-after-free in AP4_UnknownAtom::~AP4_UnknownAtom at Ap4Atom.cpp, leading to a Denial of Service (DoS),…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-30806

Published Apr 2, 2024

An issue was discovered in Bento4 v1.6.0-641-2-g1529b83. There is a heap overflow in AP4_Dec3Atom::AP4_Dec3Atom at Ap4Dec3Atom.cpp, leading to a Denial of Service (DoS), as demons…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-31005

Published Apr 2, 2024

An issue in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the Ap4MdhdAtom.cpp,AP4_MdhdAtom::AP4_MdhdAtom,mp4fragment

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-31004

Published Apr 2, 2024

An issue in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the Ap4StsdAtom.cpp,AP4_StsdAtom::AP4_StsdAtom,mp4fragment.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-31003

Published Apr 2, 2024

Buffer Overflow vulnerability in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the AP4_MemoryByteStream::WritePartial at Ap4ByteStream.cpp.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-31002

Published Apr 2, 2024

Buffer Overflow vulnerability in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the AP4 BitReader::ReadCache() at Ap4Utils.cpp component.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-24155

Published Feb 29, 2024

Bento4 v1.5.1-628 contains a Memory leak on AP4_Movie::AP4_Movie, parsing tracks and added into m_Tracks list, but mp42aac cannot correctly delete when we got an no audio track fo…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-25454

Published Feb 9, 2024

Bento4 v1.6.0-640 was discovered to contain a NULL pointer dereference via the AP4_DescriptorFinder::Test() function.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-25453

Published Feb 9, 2024

Bento4 v1.6.0-640 was discovered to contain a NULL pointer dereference via the AP4_StszAtom::GetSampleSize() function.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-25452

Published Feb 9, 2024

Bento4 v1.6.0-640 was discovered to contain an out-of-memory bug via the AP4_UrlAtom::AP4_UrlAtom() function.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-25451

Published Feb 9, 2024

Bento4 v1.6.0-640 was discovered to contain an out-of-memory bug via the AP4_DataBuffer::ReallocateBuffer() function.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-38666

Published Aug 22, 2023

Bento4 v1.6.0-639 was discovered to contain a segmentation violation via the AP4_Processor::ProcessFragments function in mp4encrypt.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 156 CVEsPage 1 of 7