Lucene search

K
cve[email protected]CVE-2007-6681
HistoryJan 17, 2008 - 1:00 a.m.

CVE-2007-6681

2008-01-1701:00:00
CWE-119
web.nvd.nist.gov
38
cve-2007-6681
videolan
vlc
buffer overflow
demux
subtitle
nvd
security
vulnerability
exploit
remote code execution

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.6 High

AI Score

Confidence

Low

0.304 Low

EPSS

Percentile

97.0%

Stack-based buffer overflow in modules/demux/subtitle.c in VideoLAN VLC 0.8.6d allows remote attackers to execute arbitrary code via a long subtitle in a (1) MicroDvd, (2) SSA, and (3) Vplayer file.

Affected configurations

NVD
Node
videolanvlcRange0.8.6d
CPENameOperatorVersion
videolan:vlcvideolan vlcle0.8.6d

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.6 High

AI Score

Confidence

Low

0.304 Low

EPSS

Percentile

97.0%