Bento4 Axiosys Bento4

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Axiosys Bento4.

By the Year

In 2026 there have been 0 vulnerabilities in Axiosys Bento4. Last year, in 2025 Bento4 had 10 security vulnerabilities published. Right now, Bento4 is on track to have less security vulnerabilities in 2026 than it did last year.




Year Vulnerabilities Average Score
2026 0 0.00
2025 10 6.30
2024 13 6.55
2023 5 5.50
2022 58 6.62
2021 17 7.13
2020 0 0.00
2019 26 6.50
2018 23 7.80

It may take a day or so for new Bento4 vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Axiosys Bento4 Security Vulnerabilities

Info Leak via Mp4Fragment in Bento4 v1.6.0-641
CVE-2025-25942 - February 19, 2025

An issue in Bento4 v1.6.0-641 allows an attacker to obtain sensitive information via the the mp4fragment tool when processing invalid files. Specifically, memory allocated in SampleArray::SampleArray in Mp4Fragment.cpp is not properly released.

Bento4 1.6.0-641 Buffer Overflow in AP4_Stz2Atom via Ap4Stz2Atom.cpp
CVE-2025-25943 - February 19, 2025

Buffer Overflow vulnerability in Bento4 v.1.6.0-641 allows a local attacker to execute arbitrary code via the AP4_Stz2Atom::AP4_Stz2Atom component located in Ap4Stz2Atom.cpp.

Bento4 v1.6.0 Buffer Overflow in Ap4RtpAtom via mp4fragment
CVE-2025-25944 - February 19, 2025

Buffer Overflow vulnerability in Bento4 v.1.6.0-641 allows a local attacker to execute arbitrary code via the Ap4RtpAtom.cpp, specifically in AP4_RtpAtom::AP4_RtpAtom, during the execution of mp4fragment with a crafted MP4 input file.

Bento4 1.6.0-641 Mp4Fragment.cpp Info Disclosure
CVE-2025-25945 - February 19, 2025

An issue in Bento4 v1.6.0-641 allows an attacker to obtain sensitive information via the the Mp4Fragment.cpp and in AP4_DescriptorFactory::CreateDescriptorFromStream at Ap4DescriptorFactory.cpp.

Bento4 v1.6.0-641 Memory Leak in mp4encrypt (AP4_MarlinIpmpEncryptingProcessor)
CVE-2025-25946 - February 19, 2025

An issue in Bento4 v1.6.0-641 allows an attacker to cause a memory leak via Ap4Marlin.cpp and Ap4Processor.cpp, specifically in AP4_MarlinIpmpEncryptingProcessor::Initialize and AP4_Processor::Process, during the execution of mp4encrypt with a specially crafted MP4 input file.

Segfault via RemoveChild in Bento4 v1.6.0-641 mp4encrypt
CVE-2025-25947 - February 19, 2025

An issue in Bento4 v1.6.0-641 allows an attacker to trigger a segmentation fault via Ap4Atom.cpp, specifically in AP4_AtomParent::RemoveChild, during the execution of mp4encrypt with a specially crafted MP4 input file.

Bento4 1.6.0-641: Remote FP Exception Div-by-Zero in AP4_TfraAtom causes DoS
CVE-2024-57598 - February 05, 2025

A floating point exception (divide-by-zero) vulnerability was discovered in Bento4 1.6.0-641 in function AP4_TfraAtom() of Ap4TfraAtom.cpp which allows a remote attacker to cause a denial of service vulnerability.

Axiomatic Bento4 <=1.6.0-641: AP4_DataBuffer GetData Heap Overflow
CVE-2025-0870 5.9 - Medium - January 30, 2025

A vulnerability was found in Axiomatic Bento4 up to 1.6.0-641. It has been rated as critical. Affected by this issue is the function AP4_DataBuffer::GetData in the library Ap4DataBuffer.h. The manipulation leads to heap-based buffer overflow. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available.

Buffer Overflow

Critical Heap Buffer Overflow in Axiomatic Bento4 <=1.6.0 (mp42aac)
CVE-2025-0753 6.5 - Medium - January 27, 2025

A vulnerability classified as critical was found in Axiomatic Bento4 up to 1.6.0. This vulnerability affects the function AP4_StdcFileByteStream::ReadPartial of the component mp42aac. The manipulation leads to heap-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

Buffer Overflow

Heap Buffer Overflow in Axiomatic Bento4 mp42aac (up to 1.6.0)
CVE-2025-0751 6.5 - Medium - January 27, 2025

A vulnerability classified as critical has been found in Axiomatic Bento4 up to 1.6.0. This affects the function AP4_BitReader::ReadBits of the component mp42aac. The manipulation leads to heap-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

Buffer Overflow

Bento4 1.6.0 Heap Overflow in AP4_Dec3Atom (DoS)
CVE-2024-30806 - April 02, 2024

An issue was discovered in Bento4 v1.6.0-641-2-g1529b83. There is a heap overflow in AP4_Dec3Atom::AP4_Dec3Atom at Ap4Dec3Atom.cpp, leading to a Denial of Service (DoS), as demonstrated by mp42aac.

Heap UAF DoS in Bento4 v1.6.0-641-2 via AP4_UnknownAtom
CVE-2024-30807 - April 02, 2024

An issue was discovered in Bento4 v1.6.0-641-2-g1529b83. There is a heap-use-after-free in AP4_UnknownAtom::~AP4_UnknownAtom at Ap4Atom.cpp, leading to a Denial of Service (DoS), as demonstrated by mp42ts.

Bento4 v1.6.0 DoS via heap-use-after-free in AP4_SubStream
CVE-2024-30808 - April 02, 2024

An issue was discovered in Bento4 v1.6.0-641-2-g1529b83. There is a heap-use-after-free in AP4_SubStream::~AP4_SubStream at Ap4ByteStream.cpp, leading to a Denial of Service (DoS), as demonstrated by mp42ts.

Heap HAU in Bento4 v1.6.0 (AP4_Sample) Causes DoS via mp42ts
CVE-2024-30809 - April 02, 2024

An issue was discovered in Bento4 v1.6.0-641-2-g1529b83. There is a heap-use-after-free in Ap4Sample.h in AP4_Sample::GetOffset() const, leading to a Denial of Service (DoS), as demonstrated by mp42ts.

Bento4 1.6.0-641 Buffer Overflow (AP4_MemoryByteStream::WritePartial) RCE
CVE-2024-31003 - April 02, 2024

Buffer Overflow vulnerability in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the AP4_MemoryByteStream::WritePartial at Ap4ByteStream.cpp.

Bento4 v1.6.0-641 Remote Code Execution via AP4_MdhdAtom
CVE-2024-31005 - April 02, 2024

An issue in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the Ap4MdhdAtom.cpp,AP4_MdhdAtom::AP4_MdhdAtom,mp4fragment

Bento4 v1.6.0-641 Remote Code Exec via AP4_StsdAtom in mp4fragment
CVE-2024-31004 9.8 - Critical - April 02, 2024

An issue in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the Ap4StsdAtom.cpp,AP4_StsdAtom::AP4_StsdAtom,mp4fragment.

Bento4 v1.6.0-641 Buffer Overflow in BitReader::ReadCache()
CVE-2024-31002 - April 02, 2024

Buffer Overflow vulnerability in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the AP4 BitReader::ReadCache() at Ap4Utils.cpp component.

Memory Leak DoS in Bento4 v1.5.1-628 via MP4 Track Parsing
CVE-2024-24155 6.5 - Medium - February 29, 2024

Bento4 v1.5.1-628 contains a Memory leak on AP4_Movie::AP4_Movie, parsing tracks and added into m_Tracks list, but mp42aac cannot correctly delete when we got an no audio track found error. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted mp4 file.

Memory Leak

Bento4 v1.6.0-640 OOM in AP4_DataBuffer::ReallocateBuffer()
CVE-2024-25451 6.5 - Medium - February 09, 2024

Bento4 v1.6.0-640 was discovered to contain an out-of-memory bug via the AP4_DataBuffer::ReallocateBuffer() function.

Resource Exhaustion

Bento4 1.6.0-640 OOM via AP4_UrlAtom constructor
CVE-2024-25452 5.5 - Medium - February 09, 2024

Bento4 v1.6.0-640 was discovered to contain an out-of-memory bug via the AP4_UrlAtom::AP4_UrlAtom() function.

Resource Exhaustion

Bento4 v1.6.0-640 NULL Deref via AP4_StszAtom::GetSampleSize()
CVE-2024-25453 5.5 - Medium - February 09, 2024

Bento4 v1.6.0-640 was discovered to contain a NULL pointer dereference via the AP4_StszAtom::GetSampleSize() function.

NULL Pointer Dereference

NULL ptr deref in Bento4 1.6.0-640 via AP4_DescriptorFinder
CVE-2024-25454 5.5 - Medium - February 09, 2024

Bento4 v1.6.0-640 was discovered to contain a NULL pointer dereference via the AP4_DescriptorFinder::Test() function.

NULL Pointer Dereference

Bento4 1.6.0639 Segmentation Violation in mp4encrypt AP4_Processor::ProcessFragments
CVE-2023-38666 5.5 - Medium - August 22, 2023

Bento4 v1.6.0-639 was discovered to contain a segmentation violation via the AP4_Processor::ProcessFragments function in mp4encrypt.

OOM in Bento4 mp42aac component before v1.6.0-639
CVE-2023-29575 5.5 - Medium - April 21, 2023

Bento4 v1.6.0-639 was discovered to contain an out-of-memory bug in the mp42aac component.

Allocation of Resources Without Limits or Throttling

Bento4 v1.6.0-639 OOM in mp4info component
CVE-2023-29573 5.5 - Medium - April 13, 2023

Bento4 v1.6.0-639 was discovered to contain an out-of-memory bug in the mp4info component.

Allocation of Resources Without Limits or Throttling

Bento4 v1.6.0-639 mp42avc OOM Vulnerability
CVE-2023-29574 5.5 - Medium - April 12, 2023

Bento4 v1.6.0-639 was discovered to contain an out-of-memory bug in the mp42avc component.

Segmentation fault in Bento4 1.6.0-639 via AP4_TrunAtom::SetDataOffset
CVE-2023-29576 5.5 - Medium - April 11, 2023

Bento4 v1.6.0-639 was discovered to contain a segmentation violation via the AP4_TrunAtom::SetDataOffset(int) function in Ap4TrunAtom.h.

Out-of-bounds Read

Bento4 <=1.6.0-639 Heap Overflow in mp42aac Remote
CVE-2022-4584 8.8 - High - December 17, 2022

A vulnerability was found in Axiomatic Bento4 up to 1.6.0-639. It has been rated as critical. Affected by this issue is some unknown functionality of the component mp42aac. The manipulation leads to heap-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-216170 is the identifier assigned to this vulnerability.

Heap-based Buffer Overflow

Critical Heap Overflow in Axiomatic Bento4's mp4info: Remote Exploit
CVE-2022-3974 8.8 - High - November 13, 2022

A vulnerability classified as critical was found in Axiomatic Bento4. Affected by this vulnerability is the function AP4_StdcFileByteStream::ReadPartial of the file Ap4StdCFileByteStream.cpp of the component mp4info. The manipulation leads to heap-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-213553 was assigned to this vulnerability.

Memory Corruption

Remote DoS in Axiomatic Bento4 mp4tag ParseCommandLine
CVE-2022-3809 6.5 - Medium - November 02, 2022

A vulnerability was found in Axiomatic Bento4 and classified as problematic. Affected by this issue is the function ParseCommandLine of the file Mp4Tag/Mp4Tag.cpp of the component mp4tag. The manipulation leads to denial of service. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-212666 is the identifier assigned to this vulnerability.

Improper Resource Shutdown or Release

Bento4 mp42hevc DS: AP4_File::AP4_File Remote exploit
CVE-2022-3810 6.5 - Medium - November 02, 2022

A vulnerability was found in Axiomatic Bento4. It has been classified as problematic. This affects the function AP4_File::AP4_File of the file Mp42Hevc.cpp of the component mp42hevc. The manipulation leads to denial of service. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-212667.

Improper Resource Shutdown or Release

Bento4 mp4edit Remote Memory Leak
CVE-2022-3813 6.5 - Medium - November 01, 2022

A vulnerability classified as problematic has been found in Axiomatic Bento4. This affects an unknown part of the component mp4edit. The manipulation leads to memory leak. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-212679.

Improper Resource Shutdown or Release

Axiomatic Bento4 mp4mux Remote Memory Leak (CVE-2022-3817)
CVE-2022-3817 6.5 - Medium - November 01, 2022

A vulnerability has been found in Axiomatic Bento4 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component mp4mux. The manipulation leads to memory leak. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-212683.

Improper Resource Shutdown or Release

Bento4 mp4decrypt Mem Leak Remote RCE
CVE-2022-3816 6.5 - Medium - November 01, 2022

A vulnerability, which was classified as problematic, was found in Axiomatic Bento4. Affected is an unknown function of the component mp4decrypt. The manipulation leads to memory leak. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-212682 is the identifier assigned to this vulnerability.

Improper Resource Shutdown or Release

Bento4 mp4decrypt Memory Leak via Remote Abuse
CVE-2022-3815 6.5 - Medium - November 01, 2022

A vulnerability, which was classified as problematic, has been found in Axiomatic Bento4. This issue affects some unknown processing of the component mp4decrypt. The manipulation leads to memory leak. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-212681 was assigned to this vulnerability.

Improper Resource Shutdown or Release

Bento4 mp4decrypt Remote Mem Leak
CVE-2022-3814 6.5 - Medium - November 01, 2022

A vulnerability classified as problematic was found in Axiomatic Bento4. This vulnerability affects unknown code of the component mp4decrypt. The manipulation leads to memory leak. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-212680.

Improper Resource Shutdown or Release

Axiomatic Bento4 mp4encrypt Memory Leak via AP4_ContainerAtom
CVE-2022-3812 6.5 - Medium - November 01, 2022

A vulnerability was found in Axiomatic Bento4. It has been rated as problematic. Affected by this issue is the function AP4_ContainerAtom::AP4_ContainerAtom of the component mp4encrypt. The manipulation leads to memory leak. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-212678 is the identifier assigned to this vulnerability.

Memory Leak

Bento4 Remote Resource Exhaustion via Incomplete Fix Exploit
CVE-2022-3807 6.5 - Medium - November 01, 2022

A vulnerability was found in Axiomatic Bento4. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Incomplete Fix CVE-2019-13238. The manipulation leads to resource consumption. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-212660.

Unchecked Return Value

Bento4 Avcinfo Heap Buffer Overflow CVE-2022-3785
CVE-2022-3785 7.8 - High - October 31, 2022

A vulnerability, which was classified as critical, has been found in Axiomatic Bento4. Affected by this issue is the function AP4_DataBuffer::SetDataSize of the component Avcinfo. The manipulation leads to heap-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-212564.

Memory Corruption

Bento4 mp4hls Heap Buffer Overflow (CVE-2022-3784)
CVE-2022-3784 7.8 - High - October 31, 2022

A vulnerability classified as critical was found in Axiomatic Bento4 5e7bb34. Affected by this vulnerability is the function AP4_Mp4AudioDsiParser::ReadBits of the file Ap4Mp4AudioInfo.cpp of the component mp4hls. The manipulation leads to heap-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-212563.

Memory Corruption

Critical Heap Overflow in Axiomatic Bento4 mp42aac WritePartial
CVE-2022-3667 7.5 - High - October 26, 2022

A vulnerability, which was classified as critical, was found in Axiomatic Bento4. This affects the function AP4_MemoryByteStream::WritePartial of the file Ap4ByteStream.cpp of the component mp42aac. The manipulation leads to heap-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-212007.

Memory Corruption

Axiomatic Bento4 mp42hevc Heap BUF Overflow
CVE-2022-3670 7.8 - High - October 26, 2022

A vulnerability was found in Axiomatic Bento4. It has been classified as critical. Affected is the function WriteSample of the component mp42hevc. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-212010 is the identifier assigned to this vulnerability.

Memory Corruption

Memory Leak in Bento4 mp4edit's AP4_AvccAtom::Create Remote Exploit
CVE-2022-3669 5.5 - Medium - October 26, 2022

A vulnerability was found in Axiomatic Bento4 and classified as problematic. This issue affects the function AP4_AvccAtom::Create of the component mp4edit. The manipulation leads to memory leak. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-212009 was assigned to this vulnerability.

Memory Leak

Bento4 mp4edit Remote Memory Leak via CreateAtomFromStream
CVE-2022-3668 5.5 - Medium - October 26, 2022

A vulnerability has been found in Axiomatic Bento4 and classified as problematic. This vulnerability affects the function AP4_AtomFactory::CreateAtomFromStream of the component mp4edit. The manipulation leads to memory leak. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-212008.

Memory Leak

Heap overrun in Axiomatic Bento4s avcinfo (AvcInfo.cpp)
CVE-2022-3665 7.8 - High - October 26, 2022

A vulnerability classified as critical was found in Axiomatic Bento4. Affected by this vulnerability is an unknown functionality of the file AvcInfo.cpp of the component avcinfo. The manipulation leads to heap-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-212005 was assigned to this vulnerability.

Memory Corruption

Bento4 mp42ts UAF via AP4_LinearReader::Advance
CVE-2022-3666 7.8 - High - October 26, 2022

A vulnerability, which was classified as critical, has been found in Axiomatic Bento4. Affected by this issue is the function AP4_LinearReader::Advance of the file Ap4LinearReader.cpp of the component mp42ts. The manipulation leads to use after free. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-212006 is the identifier assigned to this vulnerability.

Dangling pointer

Bento4 GetOffset UAF Remote Vulnerability (CVE-2022-3662)
CVE-2022-3662 7.8 - High - October 26, 2022

A vulnerability was found in Axiomatic Bento4. It has been declared as critical. This vulnerability affects the function GetOffset of the file Ap4Sample.h of the component mp42hls. The manipulation leads to use after free. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-212002 is the identifier assigned to this vulnerability.

Dangling pointer

Bento4 MP4fragment AP4_StsdAtom Null Deref Remote Exploit
CVE-2022-3663 5.5 - Medium - October 26, 2022

A vulnerability was found in Axiomatic Bento4. It has been rated as problematic. This issue affects the function AP4_StsdAtom of the file Ap4StsdAtom.cpp of the component MP4fragment. The manipulation leads to null pointer dereference. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-212003.

NULL Pointer Dereference

Axiomatic Bento4 Heap Buffer Overflow in AP4_BitStream::WriteBytes
CVE-2022-3664 7.8 - High - October 26, 2022

A vulnerability classified as critical has been found in Axiomatic Bento4. Affected is the function AP4_BitStream::WriteBytes of the file Ap4BitStream.cpp of the component avcinfo. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-212004.

Memory Corruption

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Axiosys Bento4 or by Axiosys? Click the Watch button to subscribe.

Axiosys
Vendor

subscribe