An issue was discovered in Bento4 through v1.6.0-636. A NULL pointer dereference exists in the AP4_DescriptorFinder::Test component located in /Core/Ap4Descriptor.h. It allows an attacker to cause a denial of service (DOS).
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-35307.json"