CVE-2018-14403: Techsmith MP4V2
Critical severity, CVSS 9.8. EPSS: 2.6% chance of exploitation in the next 30 days.
MP4NameFirstMatches in mp4util.cpp in MP4v2 2.0.0 mishandles substrings of atom names, leading to use of an inappropriate data type for associated atoms. The resulting type confusion can cause out-of-bounds memory access.
Affected products
- Techsmith MP4V2: version 2.0.0 only
Published 2018-07-19. Last modified 2026-06-17.