9.8
CVSSv3

CVE-2018-14054

Published: 13/07/2018 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

A double free exists in the MP4StringProperty class in mp4property.cpp in MP4v2 2.0.0. A dangling pointer is freed again in the destructor once an exception is triggered.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

techsmith mp4v2 2.0.0

Vendor Advisories

Debian Bug report logs - #903859 CVE-2018-14054 Package: src:mp4v2; Maintainer for src:mp4v2 is Debian Multimedia Maintainers <pkg-multimedia-maintainers@listsaliothdebianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Sun, 15 Jul 2018 21:33:02 UTC Severity: important Tags: security, upstream Found i ...
A double free exists in the MP4StringProperty class in mp4propertycpp in MP4v2 200 A dangling pointer is freed again in the destructor once an exception is triggered ...