Lucene search

K
cvelistMitreCVELIST:CVE-2009-0893
HistoryOct 03, 2022 - 4:24 p.m.

CVE-2009-0893

2022-10-0316:24:11
mitre
www.cve.org
xvidcore
buffer overflows
heap memory corruption
video stream
crafted macroblock
windows media player

7.6 High

AI Score

Confidence

Low

0.087 Low

EPSS

Percentile

94.6%

Multiple heap-based buffer overflows in xvidcore/src/decoder.c in the xvidcore library in Xvid before 1.2.2, as used by Windows Media Player and other applications, allow remote attackers to execute arbitrary code by providing a crafted macroblock (aka MBlock) number in a video stream in a crafted movie file that triggers heap memory corruption, related to a “missing resync marker range check” and the (1) decoder_iframe, (2) decoder_pframe, and (3) decoder_bframe functions.

7.6 High

AI Score

Confidence

Low

0.087 Low

EPSS

Percentile

94.6%

Related for CVELIST:CVE-2009-0893