The Mp4v2 Project maintains a focused media-processing library for reading and writing MPEG-4 files, a task embedded across multimedia applications, media players, and transcoding pipelines where file-format parsing is critical. Its vulnerabilities cluster around resource-management and memory-safety weaknesses—improper resource shutdown, memory leaks, out-of-bounds writes, and unthrottled allocation—reflecting the low-level parsing and buffer-handling demands of a binary container format library. Defenders should monitor this vendor's advisories for downstream products that integrate the library; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mp4v2 Project over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-29578HIGH mp4v2 v2.0.0 was discovered to contain a heap buffer overflow via the mp4v2::impl::MP4StringProperty::~MP4StringProperty() function at src/mp4property.cpp. | Apr 24, 2023 | 8.8 | 27 | NO | NO |
CVE-2023-29584HIGH mp4v2 v2.0.0 was discovered to contain a heap buffer overflow via the MP4GetVideoProfileLevel function at /src/mp4.cpp. | Apr 14, 2023 | 8.8 | 27 | NO | NO |
CVE-2018-7339HIGH The MP4Atom class in mp4atom.cpp in MP4v2 through 2.0.0 mishandles Entry Number validation for the MP4 Table Property, which allows remote attackers to cause a denial of service (o | Feb 23, 2018 | 8.8 | 26 | NO | NO |
CVE-2023-33718HIGH mp4v2 v2.1.3 was discovered to contain a memory leak via MP4File::ReadString() at mp4file_io.cpp | May 31, 2023 | 8.8 | 25 | NO | NO |
CVE-2018-17236MEDIUM The function MP4Free() in mp4property.cpp in libmp4v2 2.1.0 internally calls free() on a invalid pointer, raising a SIGABRT signal. | Sep 20, 2018 | 6.5 | 22 | NO | NO |
CVE-2018-17235MEDIUM The function mp4v2::impl::MP4Track::FinishSdtp() in mp4track.cpp in libmp4v2 2.1.0 mishandles compatibleBrand while processing a crafted mp4 file, which leads to a heap-based buffe | Sep 20, 2018 | 6.5 | 22 | NO | NO |
CVE-2023-33720MEDIUM mp4v2 v2.1.2 was discovered to contain a memory leak via the class MP4BytesProperty. | May 26, 2023 | 6.5 | 20 | NO | NO |
CVE-2023-1450MEDIUM A vulnerability was found in MP4v2 2.1.2 and classified as problematic. This issue affects the function DumpTrack of the file mp4trackdump.cpp. The manipulation leads to denial of | Mar 17, 2023 | 5.5 | 20 | NO | NO |
CVE-2023-33717MEDIUM mp4v2 v2.1.3 was discovered to contain a memory leak when a method calling MP4File::ReadBytes() had allocated memory but did not catch exceptions thrown by ReadBytes() | Jun 2, 2023 | 5.5 | 18 | NO | NO |
CVE-2023-33719MEDIUM mp4v2 v2.1.3 was discovered to contain a memory leak via MP4SdpAtom::Read() at atom_sdp.cpp | Jun 1, 2023 | 5.5 | 18 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mp4v2 Project.
Media articles that mention a CVE ID that affects a product developed by Mp4v2 Project — matched by CVE ID, not by vendor name.