216.73.216.233

CVE-2026-5236

· Published 31/03/2026 23:17 · Modified 01/04/2026 14:23

Labels: CVE-2026-5236 2026-03-31CVE-2026-5236CWE-119[email protected]

Essential information

Published
31/03/2026 23:17
Modified
01/04/2026 14:23
Author
Creator
CVSS
4.8 MEDIUM (v3) 4.8 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

A vulnerability was identified in Axiomatic Bento4 up to 1.6.0-641. Affected is the function AP4_BitReader::SkipBits of the file Ap4Dac4Atom.cpp of the component DSI v1 Parser. Such manipulation of the argument n_presentations leads to heap-based buffer overflow. The attack needs to be performed locally. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.

NVD status

Status
Awaiting Analysis — CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
axiomatic / bento4 cpe:2.3:a:axiomatic:bento4:*:*:*:*:*:*:*:*
axiomatic / bento4 cpe:2.3:a:axiomatic:bento4:<1.6.0-641:*:*:*:*:*:*:*

References