Lucene search

K
cve[email protected]CVE-2010-4294
HistoryDec 06, 2010 - 9:05 p.m.

CVE-2010-4294

2010-12-0621:05:49
CWE-94
web.nvd.nist.gov
28
vmware
movie decoder
cve-2010-4294
security vulnerability
remote code execution
denial of service

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.8 High

AI Score

Confidence

Low

0.114 Low

EPSS

Percentile

95.2%

The frame decompression functionality in the VMnc media codec in VMware Movie Decoder before 6.5.5 build 328052 and 7.x before 7.1.2 build 301548, VMware Workstation 6.5.x before 6.5.5 build 328052 and 7.x before 7.1.2 build 301548 on Windows, VMware Player 2.5.x before 2.5.5 build 246459 and 3.x before 3.1.2 build 301548 on Windows, and VMware Server 2.x on Windows does not properly validate an unspecified size field, which allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted video file.

Affected configurations

NVD
Node
vmwaremovie_decoderRange6.5.5
OR
vmwaremovie_decoderMatch6.5.3
OR
vmwaremovie_decoderMatch6.5.4
OR
vmwaremovie_decoderMatch7.0
OR
vmwaremovie_decoderMatch7.1.2
AND
microsoftwindows
Node
vmwareworkstationMatch6.5.0
OR
vmwareworkstationMatch6.5.1
OR
vmwareworkstationMatch6.5.2
OR
vmwareworkstationMatch6.5.3
OR
vmwareworkstationMatch6.5.4
OR
vmwareworkstationMatch6.5.5
OR
vmwareworkstationMatch7.0
OR
vmwareworkstationMatch7.0.1
OR
vmwareworkstationMatch7.1
OR
vmwareworkstationMatch7.1.1
OR
vmwareworkstationMatch7.1.2
AND
microsoftwindows
Node
vmwareplayerMatch2.5
OR
vmwareplayerMatch2.5.1
OR
vmwareplayerMatch2.5.2
OR
vmwareplayerMatch2.5.3
OR
vmwareplayerMatch2.5.4
OR
vmwareplayerMatch2.5.5
OR
vmwareplayerMatch3.0
OR
vmwareplayerMatch3.0.1
OR
vmwareplayerMatch3.1
OR
vmwareplayerMatch3.1.1
OR
vmwareplayerMatch3.1.2
AND
microsoftwindows
Node
vmwareserverMatch2.0.0
OR
vmwareserverMatch2.0.1
OR
vmwareserverMatch2.0.2
AND
microsoftwindows

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.8 High

AI Score

Confidence

Low

0.114 Low

EPSS

Percentile

95.2%