CVE-2018-14543: Axiosys BENTO4

Medium severity, CVSS 5.5. EPSS: 0.8% chance of exploitation in the next 30 days.

There exists one NULL pointer dereference vulnerability in AP4_JsonInspector::AddField in Ap4Atom.cpp in Bento4 1.5.1-624, which can allow attackers to cause a denial-of-service via a crafted mp4 file. This vulnerability can be triggered by the executable mp4dump.

Affected products

  • Axiosys BENTO4: version 1.5.1-624 only

Published 2018-07-23. Last modified 2026-06-17.