Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Axiosys

First CVE: Sep 6, 2017Active for: 9 yearsTotal CVEs: 156
27.4
VTI Score
Low

Axiosys maintains a narrow but high-impact portfolio centered on the Bento4 multimedia framework, a widely embedded toolkit for MPEG-4 and media file processing that appears in streaming platforms, broadcast systems, and media-handling applications across the industry. Despite the focused product scope, the vendor's vulnerability profile reflects the memory-unsafe implementation and parser complexity inherent to low-level media codec work: recurring weakness classes cluster around NULL-pointer dereferences, out-of-bounds memory access (both reads and writes), and buffer-boundary violations that are characteristic of native C/C++ media libraries. The modest disclosure volume over time, combined with the structural nature of these flaws in parsing and format-handling code, positions this vendor as a critical supply-chain component where a single flaw can propagate widely to any downstream application bundling the library. Defenders should inventory products that integrate Bento4 and track this vendor's releases closely; media processing pipelines and streaming infrastructure should be treated as high-priority targets for patching. Current vulnerability severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
156
Total CVEs
More Total CVEs than 100% of tracked vendors
19.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 100% of tracked vendors
6.9
Avg CVSS Score
Higher Avg CVSS Score than 48% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Axiosys over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 6, 2017
8 years ago
Most Recent CVE
Aug 5, 2025
354 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (156 CVEs).

156 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-14532CRITICAL
An issue was discovered in Bento4 1.5.1-624. There is a heap-based buffer over-read in AP4_Mpeg2TsVideoSampleStream::WriteSample in Core/Ap4Mpeg2Ts.cpp after a call from Mp42Hls.cp
Jul 23, 20189.830NONO
CVE-2018-14531CRITICAL
An issue was discovered in Bento4 1.5.1-624. There is an unspecified "heap-buffer-overflow" crash in the AP4_HvccAtom class in Core/Ap4HvccAtom.cpp.
Jul 23, 20189.830NONO
CVE-2024-31002CRITICAL
Buffer Overflow vulnerability in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the AP4 BitReader::ReadCache() at Ap4Utils.cpp component.
Apr 2, 20249.829NONO
CVE-2022-3974HIGH
A vulnerability classified as critical was found in Axiomatic Bento4. Affected by this vulnerability is the function AP4_StdcFileByteStream::ReadPartial of the file Ap4StdCFileByte
Nov 13, 20228.829NONO
CVE-2022-4584HIGH
A vulnerability was found in Axiomatic Bento4 up to 1.6.0-639. It has been rated as critical. Affected by this issue is some unknown functionality of the component mp42aac. The man
Dec 17, 20228.828NONO
CVE-2022-41430HIGH
Bento4 v1.6.0-639 was discovered to contain a heap overflow via the AP4_BitReader::ReadBit function in mp4mux.
Oct 3, 20228.828NONO
CVE-2019-15049HIGH
An issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer over-read in the AP4_Dec3Atom class at Core/Ap4Dec3Atom.cpp.
Aug 14, 20198.828NONO
CVE-2018-13846CRITICAL
An issue has been found in Bento4 1.5.1-624. AP4_Mpeg2TsVideoSampleStream::WriteSample in Core/Ap4Mpeg2Ts.cpp has a heap-based buffer over-read after a call from Mp42Ts.cpp, a rela
Jul 10, 20189.828NONO
CVE-2019-15050HIGH
An issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer over-read in the AP4_AvccAtom class at Core/Ap4AvccAtom.cpp.
Aug 14, 20198.827NONO
CVE-2019-15048HIGH
An issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer overflow in the AP4_RtpAtom class at Core/Ap4RtpAtom.cpp.
Aug 14, 20198.827NONO
View all 156 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products156 CVEs
62%
35%
Severity distribution among all CVEs352,708 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local49 (31.4%)
Network107 (68.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low153 (98.1%)
High3 (1.9%)
Unknown0 (0.0%)
User Interaction
None29 (18.6%)
Unknown0 (0.0%)
Required127 (81.4%)
Privileges Required
Low3 (1.9%)
High1 (0.6%)
None152 (97.4%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (156 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Axiosys.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Axiosys — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Axiosys's Products

View all 2 CNAs →

Top CWEs