Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://github.com/axiomatic-systems/Bento4/issues/1092 |
|
Tue, 29 Sep 2026 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Integer Underflow in Bento4 AVCC/HVCc Parsing Causes Denial of Service |
Tue, 29 Sep 2026 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Integer Underflow in Bento4 AVCC/HVCc Atom Parsers Leading to Denial of Service | |
| Weaknesses | CWE-193 |
Tue, 29 Sep 2026 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-191 | |
| Metrics |
cvssV3_1
|
Sun, 27 Sep 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Axiomatic
Axiomatic bento4 |
|
| Vendors & Products |
Axiomatic
Axiomatic bento4 |
Sat, 26 Sep 2026 03:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Integer Underflow in Bento4 AVCC/HVCc Atom Parsers Leading to Denial of Service | |
| Weaknesses | CWE-193 |
Thu, 24 Sep 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Bento4 1.6.0.0 contains an integer underflow vulnerability in the avcC and hvcC configuration atom parsers. A specially crafted MP4 file containing an atom with a declared size smaller than AP4_ATOM_HEADER_SIZE can cause AP4_AvccAtom::Create() or AP4_HvccAtom::Create() to underflow the payload-size calculation. The resulting oversized buffer operation can cause invalid or NULL pointers to be passed to the AP4_DataBuffer copy path, resulting in application termination and denial of service. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-09-29T02:36:24.697Z
Reserved: 2026-09-10T00:00:00.000Z
Link: CVE-2026-88377
Updated: 2026-09-29T02:35:52.088Z
Status : Deferred
Published: 2026-09-24T17:17:07.433
Modified: 2026-09-29T03:17:20.920
Link: CVE-2026-88377
No data.
OpenCVE Enrichment
Updated: 2026-09-29T07:00:08Z