{"id":"CVE-2026-88376","published":"2026-09-24T17:17:07.313","lastModified":"2026-09-24T21:08:55.030","description":"Bento4 1.6.0.0 contains an integer underflow vulnerability in AP4_AvccAtom::Create() and AP4_HvccAtom::Create(). A specially crafted MP4 file containing an avcC or hvcC atom with a declared size smaller than the atom header size can cause the payload-size calculation to wrap to a large unsigned value. The resulting invalid buffer allocation and copy operations can cause application termination, leading to denial of service.","cvssScore":7.5,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwes":["CWE-191"],"vendors":[],"products":[],"references":[{"url":"https://github.com/axiomatic-systems/Bento4/issues/1091","tags":[]},{"url":"https://github.com/axiomatic-systems/Bento4/issues/1091","tags":[]}],"exploitRefs":[{"url":"https://github.com/axiomatic-systems/Bento4/issues/1091","tags":[]},{"url":"https://github.com/axiomatic-systems/Bento4/issues/1091","tags":[]}],"hasPoc":true,"ai":null}