Bento4 is a media processing and packaging library focused on MP4 file handling and DASH streaming support, deployed across video players, transcoding pipelines, and content-delivery infrastructure. Its vulnerability footprint concentrates in a single product and recurs through memory-safety weakness classes including NULL-pointer dereferences, out-of-bounds reads and writes, buffer-boundary violations, and type-confusion conditions that are typical of native-code media parsers handling untrusted file input. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bento4 over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-14644HIGH A heap-based buffer overflow was discovered in the AP4_HdlrAtom class in Bento4 1.5.0-617. The vulnerability causes an out-of-bounds write, which leads to remote denial of service | Sep 21, 2017 | 8.8 | 27 | NO | NO |
CVE-2017-14647HIGH A heap-based buffer overflow was discovered in AP4_VisualSampleEntry::ReadFields in Core/Ap4SampleEntry.cpp in Bento4 1.5.0-617. The vulnerability causes an out-of-bounds write, wh | Sep 21, 2017 | 8.8 | 26 | NO | NO |
CVE-2017-14639HIGH AP4_VisualSampleEntry::ReadFields in Core/Ap4SampleEntry.cpp in Bento4 1.5.0-617 uses incorrect character data types, which causes a stack-based buffer underflow and out-of-bounds | Sep 21, 2017 | 8.8 | 26 | NO | NO |
CVE-2017-14261HIGH In the SDK in Bento4 1.5.0-616, the AP4_StszAtom class in Ap4StszAtom.cpp file contains a Read Memory Access Violation vulnerability. It is possible to exploit this vulnerability b | Sep 11, 2017 | 7.8 | 24 | NO | NO |
CVE-2017-14259HIGH In the SDK in Bento4 1.5.0-616, the AP4_StscAtom class in Ap4StscAtom.cpp contains a Write Memory Access Violation vulnerability. It is possible to exploit this vulnerability and p | Sep 11, 2017 | 7.8 | 23 | NO | NO |
CVE-2017-14258HIGH In the SDK in Bento4 1.5.0-616, SetItemCount in Core/Ap4StscAtom.h file contains a Write Memory Access Violation vulnerability. It is possible to exploit this vulnerability and pos | Sep 11, 2017 | 7.8 | 23 | NO | NO |
CVE-2017-14257HIGH In the SDK in Bento4 1.5.0-616, AP4_AtomSampleTable::GetSample in Core/Ap4AtomSampleTable.cpp contains a Read Memory Access Violation vulnerability. It is possible to exploit this | Sep 11, 2017 | 7.8 | 23 | NO | NO |
CVE-2017-14645MEDIUM A heap-based buffer over-read was discovered in AP4_BitStream::ReadBytes in Codecs/Ap4BitStream.cpp in Bento4 version 1.5.0-617. The vulnerability causes an application crash, whic | Sep 21, 2017 | 6.5 | 22 | NO | NO |
CVE-2017-14643MEDIUM The AP4_HdlrAtom class in Core/Ap4HdlrAtom.cpp in Bento4 version 1.5.0-617 uses an incorrect character data type, leading to a heap-based buffer over-read and application crash in | Sep 21, 2017 | 6.5 | 21 | NO | NO |
CVE-2017-14642MEDIUM A NULL pointer dereference was discovered in the AP4_HdlrAtom class in Bento4 version 1.5.0-617. The vulnerability causes a segmentation fault and application crash in AP4_StdcFile | Sep 21, 2017 | 6.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bento4.
Media articles that mention a CVE ID that affects a product developed by Bento4 — matched by CVE ID, not by vendor name.