Mp4v2
Vendor:
First CVE: Feb 23, 2018 · Active for 8 years
12
Total CVEs
More Total CVEs than 88% of tracked products
6.0
Avg CVEs / Year
Higher CVE frequency than 87% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 43% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Mp4v2 over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 23, 2018
8 years ago
Most Recent CVE
Jun 2, 2023
1,150 days ago
CVE Severity & Scoring
Mp4v212 CVEs
67%
33%
All CVEs352,708 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local5 (41.7%)
Network7 (58.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None2 (16.7%)
Unknown0 (0.0%)
Required10 (83.3%)
Privileges Required
Low2 (16.7%)
High0 (0.0%)
None10 (83.3%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-29578HIGH mp4v2 v2.0.0 was discovered to contain a heap buffer overflow via the mp4v2::impl::MP4StringProperty::~MP4StringProperty() function at src/mp4property.cpp. | Apr 24, 2023 | 8.8 | 27 | NO | NO |
CVE-2023-29584HIGH mp4v2 v2.0.0 was discovered to contain a heap buffer overflow via the MP4GetVideoProfileLevel function at /src/mp4.cpp. | Apr 14, 2023 | 8.8 | 27 | NO | NO |
CVE-2018-7339HIGH The MP4Atom class in mp4atom.cpp in MP4v2 through 2.0.0 mishandles Entry Number validation for the MP4 Table Property, which allows remote attackers to cause a denial of service (o | Feb 23, 2018 | 8.8 | 26 | NO | NO |
CVE-2023-33718HIGH mp4v2 v2.1.3 was discovered to contain a memory leak via MP4File::ReadString() at mp4file_io.cpp | May 31, 2023 | 8.8 | 25 | NO | NO |
CVE-2018-17236MEDIUM The function MP4Free() in mp4property.cpp in libmp4v2 2.1.0 internally calls free() on a invalid pointer, raising a SIGABRT signal. | Sep 20, 2018 | 6.5 | 22 | NO | NO |
CVE-2018-17235MEDIUM The function mp4v2::impl::MP4Track::FinishSdtp() in mp4track.cpp in libmp4v2 2.1.0 mishandles compatibleBrand while processing a crafted mp4 file, which leads to a heap-based buffe | Sep 20, 2018 | 6.5 | 22 | NO | NO |
CVE-2023-33720MEDIUM mp4v2 v2.1.2 was discovered to contain a memory leak via the class MP4BytesProperty. | May 26, 2023 | 6.5 | 20 | NO | NO |
CVE-2023-1450MEDIUM A vulnerability was found in MP4v2 2.1.2 and classified as problematic. This issue affects the function DumpTrack of the file mp4trackdump.cpp. The manipulation leads to denial of | Mar 17, 2023 | 5.5 | 20 | NO | NO |
CVE-2023-33717MEDIUM mp4v2 v2.1.3 was discovered to contain a memory leak when a method calling MP4File::ReadBytes() had allocated memory but did not catch exceptions thrown by ReadBytes() | Jun 2, 2023 | 5.5 | 18 | NO | NO |
CVE-2023-33719MEDIUM mp4v2 v2.1.3 was discovered to contain a memory leak via MP4SdpAtom::Read() at atom_sdp.cpp | Jun 1, 2023 | 5.5 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (12 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (12 CVEs).
Media Mentions
Signals from CVEs in this product scope (12 CVEs).
Top CNAs Publishing CVEs For Mp4v2
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.1.3 | 4 | 6.3 | 0.4% | 0 | 0 |
| 2.1.2 | 3 | 5.8 | 0.4% | 0 | 0 |
| 2.1.0 | 2 | 6.5 | 1.1% | 0 | 0 |
| 2.0.0 | 2 | 8.8 | 0.8% | 0 | 0 |