Atomicparsley is a command-line utility for editing metadata in MP4 audio and video files, presenting a narrowly scoped but specialized attack surface around media file parsing and manipulation. The observed vulnerability signal centers on out-of-bounds write conditions in its metadata-handling code, a characteristic flaw pattern in tools that process binary media structures with limited bounds checking. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Atomicparsley Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-37232CRITICAL A stack overflow vulnerability occurs in Atomicparsley 20210124.204813.840499f through APar_read64() in src/util.cpp due to the lack of buffer size of uint32_buffer while reading m | Aug 4, 2021 | 9.8 | 29 | NO | NO |
CVE-2021-37231MEDIUM A stack-buffer-overflow occurs in Atomicparsley 20210124.204813.840499f through APar_readX() in src/util.cpp while parsing a crafted mp4 file because of the missing boundary check. | Aug 4, 2021 | 5.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Atomicparsley Project.
Media articles that mention a CVE ID that affects a product developed by Atomicparsley Project — matched by CVE ID, not by vendor name.