CVE-2019-7699: Axiosys BENTO4
Medium severity, CVSS 6.5. EPSS: 1.5% chance of exploitation in the next 30 days.
A heap-based buffer over-read occurs in AP4_BitStream::WriteBytes in Codecs/Ap4BitStream.cpp in Bento4 v1.5.1-627. Remote attackers could leverage this vulnerability to cause an exception via crafted mp4 input, which leads to a denial of service.
Affected products
- Axiosys BENTO4: version 1.5.1-627 only
Published 2019-02-10. Last modified 2026-06-17.