Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-3784

Опубликовано: 31 окт. 2022
Источник: nvd
CVSS3: 6.3
CVSS3: 7.8
EPSS Низкий

Описание

A vulnerability classified as critical was found in Axiomatic Bento4 5e7bb34. Affected by this vulnerability is the function AP4_Mp4AudioDsiParser::ReadBits of the file Ap4Mp4AudioInfo.cpp of the component mp4hls. The manipulation leads to heap-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-212563.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:axiosys:bento4:1.6.0-639:*:*:*:*:*:*:*

EPSS

Процентиль: 58%
0.00369
Низкий

6.3 Medium

CVSS3

7.8 High

CVSS3

Дефекты

CWE-119
CWE-787

Связанные уязвимости

CVSS3: 6.3
ubuntu
больше 3 лет назад

A vulnerability classified as critical was found in Axiomatic Bento4 5e7bb34. Affected by this vulnerability is the function AP4_Mp4AudioDsiParser::ReadBits of the file Ap4Mp4AudioInfo.cpp of the component mp4hls. The manipulation leads to heap-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-212563.

CVSS3: 7.8
github
больше 3 лет назад

A vulnerability classified as critical was found in Axiomatic Bento4 5e7bb34. Affected by this vulnerability is the function AP4_Mp4AudioDsiParser::ReadBits of the file Ap4Mp4AudioInfo.cpp of the component mp4hls. The manipulation leads to heap-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-212563.

EPSS

Процентиль: 58%
0.00369
Низкий

6.3 Medium

CVSS3

7.8 High

CVSS3

Дефекты

CWE-119
CWE-787