CVE-2018-14544: Axiosys BENTO4

Medium severity, CVSS 5.5. EPSS: 0.8% chance of exploitation in the next 30 days.

There exists one invalid memory read bug in AP4_SampleDescription::GetFormat() in Ap4SampleDescription.h in Bento4 1.5.1-624, which can allow attackers to cause a denial-of-service via a crafted mp4 file. This vulnerability can be triggered by the executable mp42ts.

Affected products

  • Axiosys BENTO4: version 1.5.1-624 only

Published 2018-07-23. Last modified 2026-06-17.