{"api_version":"1","generated_at":"2026-07-24T19:46:30+00:00","cve":"CVE-2023-1451","urls":{"html":"https://cve.report/CVE-2023-1451","api":"https://cve.report/api/cve/CVE-2023-1451.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2023-1451","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2023-1451"},"summary":{"title":"CVE-2023-1451","description":"A vulnerability was found in MP4v2 2.1.2. It has been classified as problematic. Affected is the function mp4v2::impl::MP4Track::GetSampleFileOffset of the file mp4track.cpp. The manipulation leads to denial of service. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-223296.","state":"PUBLIC","assigner":"cna@vuldb.com","published_at":"2023-03-17 07:15:00","updated_at":"2023-11-07 04:03:00"},"problem_types":["CWE-404"],"metrics":[],"references":[{"url":"https://github.com/RichTrouble/mp4v2_mp4track_poc","name":"https://github.com/RichTrouble/mp4v2_mp4track_poc","refsource":"MISC","tags":[],"title":"GitHub - RichTrouble/mp4v2_mp4track_poc","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://vuldb.com/?ctiid.223296","name":"https://vuldb.com/?ctiid.223296","refsource":"MISC","tags":[],"title":"Login required","mime":"text/html","httpstatus":"401","archivestatus":"404"},{"url":"https://github.com/RichTrouble/mp4v2_mp4track_poc/blob/main/id_000000%2Csig_08%2Csrc_001076%2Ctime_147809374%2Cexecs_155756872%2Cop_havoc%2Crep_8","name":"https://github.com/RichTrouble/mp4v2_mp4track_poc/blob/main/id_000000%2Csig_08%2Csrc_001076%2Ctime_147809374%2Cexecs_155756872%2Cop_havoc%2Crep_8","refsource":"MISC","tags":[],"title":"mp4v2_mp4track_poc/id_000000,sig_08,src_001076,time_147809374,execs_155756872,op_havoc,rep_8 at main · RichTrouble/mp4v2_mp4track_poc · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://vuldb.com/?id.223296","name":"https://vuldb.com/?id.223296","refsource":"MISC","tags":[],"title":"Login required","mime":"text/html","httpstatus":"401","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2023-1451","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-1451","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2023","cve_id":"1451","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mp4v2_project","cpe5":"mp4v2","cpe6":"2.1.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_version":"4.0","data_type":"CVE","data_format":"MITRE","CVE_data_meta":{"ID":"CVE-2023-1451","ASSIGNER":"cna@vuldb.com","STATE":"PUBLIC"},"description":{"description_data":[{"lang":"eng","value":"A vulnerability was found in MP4v2 2.1.2. It has been classified as problematic. Affected is the function mp4v2::impl::MP4Track::GetSampleFileOffset of the file mp4track.cpp. The manipulation leads to denial of service. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-223296."},{"lang":"deu","value":"Es wurde eine problematische Schwachstelle in MP4v2 2.1.2 ausgemacht. Hiervon betroffen ist die Funktion mp4v2::impl::MP4Track::GetSampleFileOffset der Datei mp4track.cpp. Durch das Manipulieren mit unbekannten Daten kann eine denial of service-Schwachstelle ausgenutzt werden. Der Angriff hat dabei lokal zu erfolgen. Der Exploit steht zur öffentlichen Verfügung."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-404 Denial of Service","cweId":"CWE-404"}]}]},"affects":{"vendor":{"vendor_data":[{"vendor_name":"n/a","product":{"product_data":[{"product_name":"MP4v2","version":{"version_data":[{"version_affected":"=","version_value":"2.1.2"}]}}]}}]}},"references":{"reference_data":[{"url":"https://vuldb.com/?id.223296","refsource":"MISC","name":"https://vuldb.com/?id.223296"},{"url":"https://vuldb.com/?ctiid.223296","refsource":"MISC","name":"https://vuldb.com/?ctiid.223296"},{"url":"https://github.com/RichTrouble/mp4v2_mp4track_poc","refsource":"MISC","name":"https://github.com/RichTrouble/mp4v2_mp4track_poc"},{"url":"https://github.com/RichTrouble/mp4v2_mp4track_poc/blob/main/id_000000%2Csig_08%2Csrc_001076%2Ctime_147809374%2Cexecs_155756872%2Cop_havoc%2Crep_8","refsource":"MISC","name":"https://github.com/RichTrouble/mp4v2_mp4track_poc/blob/main/id_000000%2Csig_08%2Csrc_001076%2Ctime_147809374%2Cexecs_155756872%2Cop_havoc%2Crep_8"}]},"credits":[{"lang":"en","value":"ccpx (VulDB User)"}],"impact":{"cvss":[{"version":"3.1","baseScore":3.3,"vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseSeverity":"LOW"},{"version":"3.0","baseScore":3.3,"vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseSeverity":"LOW"},{"version":"2.0","baseScore":1.7,"vectorString":"AV:L/AC:L/Au:S/C:N/I:N/A:P"}]}},"nvd":{"publishedDate":"2023-03-17 07:15:00","lastModifiedDate":"2023-11-07 04:03:00","problem_types":["CWE-404"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"},"exploitabilityScore":1.8,"impactScore":3.6}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:mp4v2_project:mp4v2:2.1.2:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":null,"notes":[]}}}