Vulnerability Details CVE-2017-12475
The AP4_Processor::Process function in Core/Ap4Processor.cpp in Bento4 mp4encrypt before 1.5.0-616 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted mp4 file.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 49.0%
CVSS Severity
CVSS v3 Score 5.5
CVSS v2 Score 4.3
Products affected by CVE-2017-12475
-
cpe:2.3:a:axiosys:bento4:-
-
cpe:2.3:a:axiosys:bento4:1.2
-
cpe:2.3:a:axiosys:bento4:1.4.2-584
-
cpe:2.3:a:axiosys:bento4:1.4.2-586
-
cpe:2.3:a:axiosys:bento4:1.4.2-587
-
cpe:2.3:a:axiosys:bento4:1.4.2-588
-
cpe:2.3:a:axiosys:bento4:1.4.2-589
-
cpe:2.3:a:axiosys:bento4:1.4.2-590
-
cpe:2.3:a:axiosys:bento4:1.4.2-591
-
cpe:2.3:a:axiosys:bento4:1.4.2-592
-
cpe:2.3:a:axiosys:bento4:1.4.2-593
-
cpe:2.3:a:axiosys:bento4:1.4.2-594
-
cpe:2.3:a:axiosys:bento4:1.4.3-595
-
cpe:2.3:a:axiosys:bento4:1.4.3-596
-
cpe:2.3:a:axiosys:bento4:1.4.3-597
-
cpe:2.3:a:axiosys:bento4:1.4.3-598
-
cpe:2.3:a:axiosys:bento4:1.4.3-599
-
cpe:2.3:a:axiosys:bento4:1.4.3-600
-
cpe:2.3:a:axiosys:bento4:1.4.3-601
-
cpe:2.3:a:axiosys:bento4:1.4.3-602
-
cpe:2.3:a:axiosys:bento4:1.4.3-603
-
cpe:2.3:a:axiosys:bento4:1.4.3-604
-
cpe:2.3:a:axiosys:bento4:1.4.3-605
-
cpe:2.3:a:axiosys:bento4:1.4.3-606
-
cpe:2.3:a:axiosys:bento4:1.4.3-607
-
cpe:2.3:a:axiosys:bento4:1.4.3-608
-
cpe:2.3:a:axiosys:bento4:1.5.0-609
-
cpe:2.3:a:axiosys:bento4:1.5.0-610
-
cpe:2.3:a:axiosys:bento4:1.5.0-611
-
cpe:2.3:a:axiosys:bento4:1.5.0-612
-
cpe:2.3:a:axiosys:bento4:1.5.0-613
-
cpe:2.3:a:axiosys:bento4:1.5.0-614
-
cpe:2.3:a:axiosys:bento4:1.5.0-615