Lucene search

K
cve[email protected]CVE-2009-1564
HistoryApr 12, 2010 - 6:30 p.m.

CVE-2009-1564

2010-04-1218:30:00
CWE-119
web.nvd.nist.gov
25
cve-2009-1564
buffer overflow
vmnc.dll
vmware movie decoder
vmware
windows
avi
hextile encoding
vulnerability
nvd

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

8 High

AI Score

Confidence

Low

0.271 Low

EPSS

Percentile

96.8%

Heap-based buffer overflow in vmnc.dll in the VMnc media codec in VMware Movie Decoder before 6.5.4 Build 246459 on Windows, and the movie decoder in VMware Workstation 6.5.x before 6.5.4 build 246459, VMware Player 2.5.x before 2.5.4 build 246459, and VMware Server 2.x on Windows, allows remote attackers to execute arbitrary code via an AVI file with crafted video chunks that use HexTile encoding.

Affected configurations

NVD
Node
vmwaremovie_decoderMatch6.5.3
AND
microsoftwindows
Node
vmwareworkstationMatch6.5.0
OR
vmwareworkstationMatch6.5.1
OR
vmwareworkstationMatch6.5.2
OR
vmwareworkstationMatch6.5.3
Node
vmwareplayerMatch2.5
OR
vmwareplayerMatch2.5.1
OR
vmwareplayerMatch2.5.2
OR
vmwareplayerMatch2.5.3
Node
vmwareserverMatch2.0.0
OR
vmwareserverMatch2.0.1
OR
vmwareserverMatch2.0.2
AND
microsoftwindows

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

8 High

AI Score

Confidence

Low

0.271 Low

EPSS

Percentile

96.8%