CVE-2022-3816
Last modified
CVE-2022-3816 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. A vulnerability, which was classified as problematic, was found in Axiomatic Bento4. Affected is an unknown function of the component mp4decrypt. EPSS estimates a 0.78% chance of exploitation in the next 30 days.
Description
A vulnerability, which was classified as problematic, was found in Axiomatic Bento4. Affected is an unknown function of the component mp4decrypt. The manipulation leads to memory leak. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-212682 is the identifier assigned to this vulnerability.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Axiosys | Bento4 | 1.6.0-639 |
References
- https://github.com/axiomatic-systems/Bento4/files/9727059/POC_mp4decrypt_654515280.zipExploit, Third Party Advisory
- https://github.com/axiomatic-systems/Bento4/issues/792Issue Tracking, Third Party Advisory
- https://vuldb.com/?id.212682Third Party Advisory
- https://github.com/axiomatic-systems/Bento4/files/9727059/POC_mp4decrypt_654515280.zipExploit, Third Party Advisory
- https://github.com/axiomatic-systems/Bento4/issues/792Issue Tracking, Third Party Advisory
- https://vuldb.com/?id.212682Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-3816?
How severe is CVE-2022-3816?
How do I fix CVE-2022-3816?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-3815A vulnerability, which was classified as problematic, has be…6.5
- CVE-2022-38150In Varnish Cache 7.0.0, 7.0.1, 7.0.2, and 7.1.0, it is possi…7.5
- CVE-2022-38152An issue was discovered in wolfSSL before 5.5.0. When a TLS …7.5
- CVE-2022-38153An issue was discovered in wolfSSL before 5.5.0 (when --enab…5.9
- CVE-2022-38155TEE_Malloc in Samsung mTower through 0.3.0 allows a trusted …7.5
- CVE-2022-38156A remote command injection issues exists in the web server o…7.2
- CVE-2022-38161The Gumstix Overo SBC on the VSKS board through 2022-08-09, …7.5
- CVE-2022-38162Reflected cross-site scripting (XSS) vulnerabilities in With…6.1
- CVE-2022-38163A Drag and Drop spoof vulnerability was discovered in F-Secu…3.5
- CVE-2022-38164A vulnerability affecting F-Secure SAFE browser for Android …6.5
- CVE-2022-38165Arbitrary file write in F-Secure Policy Manager through 2022…9.8
- CVE-2022-38166In F-Secure Endpoint Protection for Windows and macOS before…7.5
Are you affected by CVE-2022-3816?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
