Lucene search

K
cve[email protected]CVE-2009-0893
HistoryOct 03, 2022 - 4:24 p.m.

CVE-2009-0893

2022-10-0316:24:11
CWE-119
web.nvd.nist.gov
24
cve-2009-0893
xvidcore library
buffer overflow
remote code execution
nvd
security vulnerability

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

7.9 High

AI Score

Confidence

Low

0.087 Low

EPSS

Percentile

94.6%

Multiple heap-based buffer overflows in xvidcore/src/decoder.c in the xvidcore library in Xvid before 1.2.2, as used by Windows Media Player and other applications, allow remote attackers to execute arbitrary code by providing a crafted macroblock (aka MBlock) number in a video stream in a crafted movie file that triggers heap memory corruption, related to a “missing resync marker range check” and the (1) decoder_iframe, (2) decoder_pframe, and (3) decoder_bframe functions.

Affected configurations

NVD
Node
xvidxvidRange1.2.1
OR
xvidxvidMatch1.1.0
OR
xvidxvidMatch1.1.1
OR
xvidxvidMatch1.1.2
OR
xvidxvidMatch1.1.3
OR
xvidxvidMatch1.2.0

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

7.9 High

AI Score

Confidence

Low

0.087 Low

EPSS

Percentile

94.6%