Vulnerabilities > Bento4 > High

DATE CVE VULNERABILITY TITLE RISK
2017-09-21 CVE-2017-14647 Out-of-bounds Write vulnerability in Bento4 1.5.0617
A heap-based buffer overflow was discovered in AP4_VisualSampleEntry::ReadFields in Core/Ap4SampleEntry.cpp in Bento4 1.5.0-617.
network
low complexity
bento4 CWE-787
8.8
2017-09-21 CVE-2017-14644 Out-of-bounds Write vulnerability in Bento4 1.5.0617
A heap-based buffer overflow was discovered in the AP4_HdlrAtom class in Bento4 1.5.0-617.
network
low complexity
bento4 CWE-787
8.8
2017-09-21 CVE-2017-14639 Type Confusion vulnerability in Bento4 1.5.0617
AP4_VisualSampleEntry::ReadFields in Core/Ap4SampleEntry.cpp in Bento4 1.5.0-617 uses incorrect character data types, which causes a stack-based buffer underflow and out-of-bounds write, leading to denial of service (application crash) or possibly unspecified other impact.
network
low complexity
bento4 CWE-843
8.8
2017-09-11 CVE-2017-14261 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Bento4 1.5.0616
In the SDK in Bento4 1.5.0-616, the AP4_StszAtom class in Ap4StszAtom.cpp file contains a Read Memory Access Violation vulnerability.
local
low complexity
bento4 CWE-119
7.8
2017-09-11 CVE-2017-14259 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Bento4 1.5.0616
In the SDK in Bento4 1.5.0-616, the AP4_StscAtom class in Ap4StscAtom.cpp contains a Write Memory Access Violation vulnerability.
local
low complexity
bento4 CWE-119
7.8
2017-09-11 CVE-2017-14258 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Bento4 1.5.0616
In the SDK in Bento4 1.5.0-616, SetItemCount in Core/Ap4StscAtom.h file contains a Write Memory Access Violation vulnerability.
local
low complexity
bento4 CWE-119
7.8
2017-09-11 CVE-2017-14257 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Bento4 1.5.0616
In the SDK in Bento4 1.5.0-616, AP4_AtomSampleTable::GetSample in Core/Ap4AtomSampleTable.cpp contains a Read Memory Access Violation vulnerability.
local
low complexity
bento4 CWE-119
7.8