Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Derekxco

#13374of 53,630
19.8Total CVSS
Vulnerabilities · 3
Medium
2
High
1
PT-2023-26539
5.5
2023-08-22
Bento4 · Bento4 · CVE-2023-38666
**Name of the Vulnerable Software and Affected Versions** Bento4 version 1.6.0-639 **Description** A segmentation violation was discovered in Bento4 via the `AP4 Processor::ProcessFragments` function in `mp4encrypt`. **Recommendations** For Bento4 version 1.6.0-639, consider disabling the `AP4 Processor::ProcessFragments` function as a temporary workaround until a patch is available.
PT-2022-24113
7.8
2022-10-31
Axiomatic · Axiomatic Bento4 · CVE-2022-3785
**Name of the Vulnerable Software and Affected Versions** Axiomatic Bento4 (affected versions not specified) **Description** A critical issue has been found in Axiomatic Bento4, affecting the function `AP4 DataBuffer::SetDataSize` of the `Avcinfo` component. This issue leads to a heap-based buffer overflow. The attack can be launched remotely. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2022-25855
6.5
2022-10-03
Bento4 · Bento4 · CVE-2022-41419
**Name of the Vulnerable Software and Affected Versions** Bento4 version 1.6.0-639 **Description** A memory leak was discovered in Bento4 via the `AP4 Processor::Process` function in the mp4encrypt binary. **Recommendations** For version 1.6.0-639, consider restricting the use of the `AP4 Processor::Process` function until a patch is available.