CVE-2026-88377
6.2 MEDIUMpublic exploit availablePublished 2026-09-24 · Updated 2026-09-29
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
Bento4 1.6.0.0 contains an integer underflow vulnerability in the avcC and hvcC configuration atom parsers. A specially crafted MP4 file containing an atom with a declared size smaller than AP4_ATOM_HEADER_SIZE can cause AP4_AvccAtom::Create() or AP4_HvccAtom::Create() to underflow the payload-size calculation. The resulting oversized buffer operation can cause invalid or NULL pointers to be passed to the AP4_DataBuffer copy path, resulting in application termination and denial of service.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weaknesses
CWE-191
Public exploit & PoC references
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- MEDIUMCVE-2026-17504
- MEDIUMCVE-2026-18747PoC
- MEDIUMCVE-2026-24077
- MEDIUMCVE-2026-61720PoC
- HIGHCVE-2026-71202PoC
- LOWCVE-2026-81881PoC
- HIGHCVE-2026-88376PoC
- HIGHCVE-2026-89028
Related by shared AI tags and CWE weakness class. Browse the full archive.