CVE-2025-8537

Source
https://cve.org/CVERecord?id=CVE-2025-8537
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-8537.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-8537
Published
2025-08-05T00:32:06.097Z
Modified
2026-07-15T01:49:17.590867688Z
Severity
  • 2.9 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
Axiomatic Bento4 mp4decrypt Mp4Decrypt.cpp SetDataSize allocation of resources
Details

A vulnerability, which was classified as problematic, was found in Axiomatic Bento4 up to 1.6.0-641. Affected is the function AP4_DataBuffer::SetDataSize of the file Mp4Decrypt.cpp of the component mp4decrypt. The manipulation leads to allocation of resources. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used.

Database specific
{
    "cna_assigner": "VulDB",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/8xxx/CVE-2025-8537.json",
    "cwe_ids": [
        "CWE-400",
        "CWE-770"
    ]
}
References

Affected packages

Git / github.com/axiomatic-systems/bento4

Affected ranges

Type
GIT
Repo
https://github.com/axiomatic-systems/bento4
Events
Database specific
{
    "cpe": "cpe:2.3:a:axiosys:bento4:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "1.6.0-641"
        },
        {
            "last_affected": "1.6.0-641"
        },
        {
            "introduced": "0"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "CPE_RANGE"
    ]
}

Affected versions

1.*
1.6.0-641
v1.*
v1.6.0-641

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-8537.json"