CVE-2017-12475: Axiosys BENTO4
Medium severity, CVSS 5.5. EPSS: 1.2% chance of exploitation in the next 30 days.
The AP4_Processor::Process function in Core/Ap4Processor.cpp in Bento4 mp4encrypt before 1.5.0-616 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted mp4 file.
Affected products
- Axiosys BENTO4: up to and including 1.5.0-615
Published 2017-09-06. Last modified 2026-06-17.