Mp4v2 is a specialized library for reading and writing MP4 multimedia files, with a narrow but substantive exposure centered on memory-management vulnerabilities. The recurring weakness pattern reflects the parsing and buffer-handling demands of processing complex media container formats, where incomplete cleanup after memory use can create resource exhaustion or state-corruption risks. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mp4v2 over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-29578HIGH mp4v2 v2.0.0 was discovered to contain a heap buffer overflow via the mp4v2::impl::MP4StringProperty::~MP4StringProperty() function at src/mp4property.cpp. | Apr 24, 2023 | 8.8 | 27 | NO | NO |
CVE-2023-29584HIGH mp4v2 v2.0.0 was discovered to contain a heap buffer overflow via the MP4GetVideoProfileLevel function at /src/mp4.cpp. | Apr 14, 2023 | 8.8 | 27 | NO | NO |
CVE-2018-7339HIGH The MP4Atom class in mp4atom.cpp in MP4v2 through 2.0.0 mishandles Entry Number validation for the MP4 Table Property, which allows remote attackers to cause a denial of service (o | Feb 23, 2018 | 8.8 | 26 | NO | NO |
CVE-2023-33718HIGH mp4v2 v2.1.3 was discovered to contain a memory leak via MP4File::ReadString() at mp4file_io.cpp | May 31, 2023 | 8.8 | 25 | NO | NO |
CVE-2018-17236MEDIUM The function MP4Free() in mp4property.cpp in libmp4v2 2.1.0 internally calls free() on a invalid pointer, raising a SIGABRT signal. | Sep 20, 2018 | 6.5 | 22 | NO | NO |
CVE-2018-17235MEDIUM The function mp4v2::impl::MP4Track::FinishSdtp() in mp4track.cpp in libmp4v2 2.1.0 mishandles compatibleBrand while processing a crafted mp4 file, which leads to a heap-based buffe | Sep 20, 2018 | 6.5 | 22 | NO | NO |
CVE-2023-33720MEDIUM mp4v2 v2.1.2 was discovered to contain a memory leak via the class MP4BytesProperty. | May 26, 2023 | 6.5 | 20 | NO | NO |
CVE-2023-1450MEDIUM A vulnerability was found in MP4v2 2.1.2 and classified as problematic. This issue affects the function DumpTrack of the file mp4trackdump.cpp. The manipulation leads to denial of | Mar 17, 2023 | 5.5 | 20 | NO | NO |
CVE-2023-33717MEDIUM mp4v2 v2.1.3 was discovered to contain a memory leak when a method calling MP4File::ReadBytes() had allocated memory but did not catch exceptions thrown by ReadBytes() | Jun 2, 2023 | 5.5 | 18 | NO | NO |
CVE-2023-33719MEDIUM mp4v2 v2.1.3 was discovered to contain a memory leak via MP4SdpAtom::Read() at atom_sdp.cpp | Jun 1, 2023 | 5.5 | 18 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mp4v2.
Media articles that mention a CVE ID that affects a product developed by Mp4v2 — matched by CVE ID, not by vendor name.