Axiosys maintains a narrow but high-impact portfolio centered on the Bento4 multimedia framework, a widely embedded toolkit for MPEG-4 and media file processing that appears in streaming platforms, broadcast systems, and media-handling applications across the industry. Despite the focused product scope, the vendor's vulnerability profile reflects the memory-unsafe implementation and parser complexity inherent to low-level media codec work: recurring weakness classes cluster around NULL-pointer dereferences, out-of-bounds memory access (both reads and writes), and buffer-boundary violations that are characteristic of native C/C++ media libraries. The modest disclosure volume over time, combined with the structural nature of these flaws in parsing and format-handling code, positions this vendor as a critical supply-chain component where a single flaw can propagate widely to any downstream application bundling the library. Defenders should inventory products that integrate Bento4 and track this vendor's releases closely; media processing pipelines and streaming infrastructure should be treated as high-priority targets for patching. Current vulnerability severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Axiosys over time
Signals from CVEs in this vendor scope (156 CVEs).
156 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-14532CRITICAL An issue was discovered in Bento4 1.5.1-624. There is a heap-based buffer over-read in AP4_Mpeg2TsVideoSampleStream::WriteSample in Core/Ap4Mpeg2Ts.cpp after a call from Mp42Hls.cp | Jul 23, 2018 | 9.8 | 30 | NO | NO |
CVE-2018-14531CRITICAL An issue was discovered in Bento4 1.5.1-624. There is an unspecified "heap-buffer-overflow" crash in the AP4_HvccAtom class in Core/Ap4HvccAtom.cpp. | Jul 23, 2018 | 9.8 | 30 | NO | NO |
CVE-2024-31002CRITICAL Buffer Overflow vulnerability in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the AP4 BitReader::ReadCache() at Ap4Utils.cpp component. | Apr 2, 2024 | 9.8 | 29 | NO | NO |
CVE-2022-3974HIGH A vulnerability classified as critical was found in Axiomatic Bento4. Affected by this vulnerability is the function AP4_StdcFileByteStream::ReadPartial of the file Ap4StdCFileByte | Nov 13, 2022 | 8.8 | 29 | NO | NO |
CVE-2022-4584HIGH A vulnerability was found in Axiomatic Bento4 up to 1.6.0-639. It has been rated as critical. Affected by this issue is some unknown functionality of the component mp42aac. The man | Dec 17, 2022 | 8.8 | 28 | NO | NO |
CVE-2022-41430HIGH Bento4 v1.6.0-639 was discovered to contain a heap overflow via the AP4_BitReader::ReadBit function in mp4mux. | Oct 3, 2022 | 8.8 | 28 | NO | NO |
CVE-2019-15049HIGH An issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer over-read in the AP4_Dec3Atom class at Core/Ap4Dec3Atom.cpp. | Aug 14, 2019 | 8.8 | 28 | NO | NO |
CVE-2018-13846CRITICAL An issue has been found in Bento4 1.5.1-624. AP4_Mpeg2TsVideoSampleStream::WriteSample in Core/Ap4Mpeg2Ts.cpp has a heap-based buffer over-read after a call from Mp42Ts.cpp, a rela | Jul 10, 2018 | 9.8 | 28 | NO | NO |
CVE-2019-15050HIGH An issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer over-read in the AP4_AvccAtom class at Core/Ap4AvccAtom.cpp. | Aug 14, 2019 | 8.8 | 27 | NO | NO |
CVE-2019-15048HIGH An issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer overflow in the AP4_RtpAtom class at Core/Ap4RtpAtom.cpp. | Aug 14, 2019 | 8.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (156 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Axiosys.
Media articles that mention a CVE ID that affects a product developed by Axiosys — matched by CVE ID, not by vendor name.