Description
An access violation in the BaseSplitterFile::Read function of Aleksoid1978 MPC-BE before commit 4341cb3 allows attackers to cause a Denial of Service (DoS) via a crafted MP4 file.
Published: 2026-07-01
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An out‑the BaseSplitterFile::Read function of the Aleksoid1978 MPC‑BE media player causes an access violation when a crafted MP4 file is processed, leading to a crash of the player. The crash terminates playback, resulting in a denial of service. This only changes the integrity of the media playback process and is a memory safety error classified as CWE‑119.

Affected Systems

The flaw exists in all builds of MPC‑BE preceding commit 4341cb3. Users running older source‑code or compiled editions before this commit are potentially at risk. No specific release numbers are cited, so every build prior to the mentioned commit should be considered vulnerable.

Risk and Exploitability

The attacker simply needs to supply a malicious MP4 file and have the victim open it with the vulnerable player; no remote code execution is required. Based on the description, the attack vector is inferred to be local or network delivery of a crafted MP4 file to a vulnerable user. The CVSS score of 5.5 indicates moderate severity for environments that rely on continuous media playback. The EPSS score is below 1% and the vulnerability is not listed in CISA’s KEV catalog, implying a low likelihood of exploitation. However, in critical or embedded systems where media playback is essential, the denial of service could be disruptive.

Generated by OpenCVE AI on July 21, 2026 at 15:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest version of MPC‑BE that includes commit 4341cb3.
  • If an update cannot be applied immediately, isolate the player from untrusted media by limiting MP4 processing to trusted sources or running the player in a sandboxed environment.
  • Implement a system watchdog or restart script that automatically restarts the media player after a crash to reduce overall downtime.

Generated by OpenCVE AI on July 21, 2026 at 15:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 21 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Title Access Violation in MPC‑BE MP4 Parser Causes Denial of Service

Fri, 17 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title Denial of Service via Crafted MP4 in MPC-BE

Mon, 13 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Title Denial of Service via Crafted MP4 in MPC-BE

Sun, 12 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title MP4 File Processing Denial of Service in MPC‑BE

Sat, 11 Jul 2026 09:00:00 +0000

Type Values Removed Values Added
Title MP4 File Processing Denial of Service in MPC‑BE

Fri, 10 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
Title MP4 File Crash Leading to Denial of Service in MPC‑BE via Out‑of‑Bounds Read

Thu, 09 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
Title MP4 File Crash Leading to Denial of Service in MPC‑BE via Out‑of‑Bounds Read

Wed, 08 Jul 2026 08:00:00 +0000

Type Values Removed Values Added
Title MPC‑BE Media Player Denial of Service via Crafted MP4 File

Tue, 07 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Title MPC‑BE Media Player Denial of Service via Crafted MP4 File

Mon, 06 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title BaseSplitterFile Access Violation Leading to Denial of Service in MPC‑BE

Mon, 06 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title BaseSplitterFile Access Violation Leading to Denial of Service in MPC‑BE

Mon, 06 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Read in MPC‑BE MP4 Parser Causes Crash

Sun, 05 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Read in MPC‑BE MP4 Parser Causes Crash

Sun, 05 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Title Access Violation in MPC‑BE MP4 Reading Causes Denial of Service

Sat, 04 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title Access Violation in MPC‑BE MP4 Reading Causes Denial of Service

Sat, 04 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Title Memory Corruption Leading to Denial-of-Service via Crafted MP4 in MPC‑BE

Fri, 03 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Memory Corruption Leading to Denial-of-Service via Crafted MP4 in MPC‑BE

Fri, 03 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title Denial of Service via Crafted MP4 File in MPC‑BE Old Builds
Weaknesses CWE-125
CWE-416

Thu, 02 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title Denial of Service via Crafted MP4 File in MPC‑BE Old Builds
Weaknesses CWE-125
CWE-416

Thu, 02 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title DoS via Access Violation in MPC-BE MP4 Parser
Weaknesses CWE-125
CWE-416

Thu, 02 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
Title DoS via Access Violation in MPC-BE MP4 Parser
Weaknesses CWE-125
CWE-416

Wed, 01 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description An access violation in the BaseSplitterFile::Read function of Aleksoid1978 MPC-BE before commit 4341cb3 allows attackers to cause a Denial of Service (DoS) via a crafted MP4 file.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-02T14:38:37.567Z

Reserved: 2026-04-06T00:00:00.000Z

Link: CVE-2026-36910

cve-icon Vulnrichment

Updated: 2026-07-02T14:38:00.153Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T15:15:08Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer