CVE-2018-14403 is a critical type confusion vulnerability in MP4v2 2.0.0, specifically within the MP4NameFirstMatches function in mp4util.cpp, affecting products like Techsmith MP4v2. This flaw arises from mishandling atom name substrings, leading to an inappropriate data type being used for associated atoms. With a CVSS score of 9.8 (CRITICAL), this vulnerability allows for unauthenticated, low-complexity network attacks that can result in complete compromise of confidentiality, integrity, and availability through out-of-bounds memory access. Despite its high severity, there is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.0.0CPE matchmatch criteria | cpe:2.3:a:techsmith:mp4v2:2.0.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.