Show filters
147 Total Results
Displaying 1-10 of 147
Sort by:
Attacker Value
Unknown

CVE-2024-39338

Disclosure Date: August 12, 2024 (last updated August 24, 2024)
axios 1.7.2 allows SSRF via unexpected behavior where requests for path relative URLs get processed as protocol relative URLs.
Attacker Value
Unknown

CVE-2024-24155

Disclosure Date: February 29, 2024 (last updated January 17, 2025)
Bento4 v1.5.1-628 contains a Memory leak on AP4_Movie::AP4_Movie, parsing tracks and added into m_Tracks list, but mp42aac cannot correctly delete when we got an no audio track found error. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted mp4 file.
Attacker Value
Unknown

CVE-2024-25454

Disclosure Date: February 09, 2024 (last updated February 13, 2024)
Bento4 v1.6.0-640 was discovered to contain a NULL pointer dereference via the AP4_DescriptorFinder::Test() function.
Attacker Value
Unknown

CVE-2024-25453

Disclosure Date: February 09, 2024 (last updated February 13, 2024)
Bento4 v1.6.0-640 was discovered to contain a NULL pointer dereference via the AP4_StszAtom::GetSampleSize() function.
Attacker Value
Unknown

CVE-2024-25452

Disclosure Date: February 09, 2024 (last updated February 13, 2024)
Bento4 v1.6.0-640 was discovered to contain an out-of-memory bug via the AP4_UrlAtom::AP4_UrlAtom() function.
Attacker Value
Unknown

CVE-2024-25451

Disclosure Date: February 09, 2024 (last updated February 13, 2024)
Bento4 v1.6.0-640 was discovered to contain an out-of-memory bug via the AP4_DataBuffer::ReallocateBuffer() function.
Attacker Value
Unknown

CVE-2023-45857

Disclosure Date: November 08, 2023 (last updated November 17, 2023)
An issue discovered in Axios 1.5.1 inadvertently reveals the confidential XSRF-TOKEN stored in cookies by including it in the HTTP header X-XSRF-TOKEN for every request made to any host allowing attackers to view sensitive information.
Attacker Value
Unknown

CVE-2023-38666

Disclosure Date: August 22, 2023 (last updated October 08, 2023)
Bento4 v1.6.0-639 was discovered to contain a segmentation violation via the AP4_Processor::ProcessFragments function in mp4encrypt.
Attacker Value
Unknown

CVE-2023-29575

Disclosure Date: April 21, 2023 (last updated October 08, 2023)
Bento4 v1.6.0-639 was discovered to contain an out-of-memory bug in the mp42aac component.
Attacker Value
Unknown

CVE-2023-29573

Disclosure Date: April 13, 2023 (last updated October 08, 2023)
Bento4 v1.6.0-639 was discovered to contain an out-of-memory bug in the mp4info component.