In Bento4 v1.5.1-624, AP4File::ParseStream in Ap4File.cpp allows remote attackers to cause a denial of service (infinite loop) via a crafted MP4 file.
An issue has been discovered in Bento4 1.5.1-624. A NULL pointer dereference can occur in AP4DataBuffer::SetData in Core/Ap4DataBuffer.cpp.
An issue has been discovered in Bento4 1.5.1-624. A SEGV can occur in AP4Processor::ProcessFragments in Core/Ap4Processor.cpp.
An issue has been discovered in Bento4 1.5.1-624. AP4MemoryByteStream::WritePartial in Core/Ap4ByteStream.cpp has a buffer over-read.
An issue has been discovered in Bento4 1.5.1-624. AP4Mp4AudioDsiParser::ReadBits in Codecs/Ap4Mp4AudioInfo.cpp has a heap-based buffer over-read.
An issue has been discovered in Bento4 1.5.1-624. AP4AvccAtom::Create in Core/Ap4AvccAtom.cpp has a heap-based buffer over-read.
An issue has been discovered in Bento4 1.5.1-624. AP4BytesToUInt16BE in Core/Ap4Utils.h has a heap-based buffer over-read after a call from the AP4Stz2Atom class.
An issue has been discovered in Bento4 1.5.1-624. A SEGV can occur in AP4Mpeg2TsAudioSampleStream::WriteSample in Core/Ap4Mpeg2Ts.cpp, a different vulnerability than CVE-2018-14532.
An issue was discovered in Bento4 1.5.1-624. There is an unspecified "heap-buffer-overflow" crash in the AP4HvccAtom class in Core/Ap4HvccAtom.cpp.
There exists one NULL pointer dereference vulnerability in AP4JsonInspector::AddField in Ap4Atom.cpp in Bento4 1.5.1-624, which can allow attackers to cause a denial-of-service via a crafted mp4 file. This vulnerability can be triggered by the executable mp4dump.
There exists one invalid memory read bug in AP4SampleDescription::GetType() in Ap4SampleDescription.h in Bento4 1.5.1-624, which can allow attackers to cause a denial-of-service via a crafted mp4 file. This vulnerability can be triggered by the executable mp42ts.
An issue was discovered in Bento4 1.5.1-624. There is a heap-based buffer over-read in AP4Mpeg2TsVideoSampleStream::WriteSample in Core/Ap4Mpeg2Ts.cpp after a call from Mp42Hls.cpp, a related issue to CVE-2018-13846.
There exists one invalid memory read bug in AP4SampleDescription::GetFormat() in Ap4SampleDescription.h in Bento4 1.5.1-624, which can allow attackers to cause a denial-of-service via a crafted mp4 file. This vulnerability can be triggered by the executable mp42ts.
An issue has been found in Bento4 1.5.1-624. It is a SEGV in AP4StszAtom::GetSampleSize in Core/Ap4StszAtom.cpp.
An issue has been found in Bento4 1.5.1-624. It is a SEGV in AP4StcoAtom::AdjustChunkOffsets in Core/Ap4StcoAtom.cpp.
An issue has been found in Bento4 1.5.1-624. AP4Mpeg2TsVideoSampleStream::WriteSample in Core/Ap4Mpeg2Ts.cpp has a heap-based buffer over-read after a call from Mp42Ts.cpp, a related issue to CVE-2018-14532.