Lucene search

K
nvd[email protected]NVD:CVE-2008-1686
HistoryApr 08, 2008 - 6:05 p.m.

CVE-2008-1686

2008-04-0818:05:00
CWE-189
web.nvd.nist.gov

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.4 High

AI Score

Confidence

Low

0.068 Low

EPSS

Percentile

93.9%

Array index vulnerability in Speex 1.1.12 and earlier, as used in libfishsound 0.9.0 and earlier, including Illiminable DirectShow Filters and Annodex Plugins for Firefox, xine-lib before 1.1.12, and many other products, allows remote attackers to execute arbitrary code via a header structure containing a negative offset, which is used to dereference a function pointer.

Affected configurations

NVD
Node
xinexine-libRange≀1.1.11.1
OR
xinexine-libMatch0.9.8
OR
xinexine-libMatch0.9.13
OR
xinexine-libMatch0.99
OR
xinexine-libMatch1.0
OR
xinexine-libMatch1.0.1
OR
xinexine-libMatch1.0.2
OR
xinexine-libMatch1.0.3a
OR
xinexine-libMatch1.1.0
OR
xinexine-libMatch1.1.1
OR
xinexine-libMatch1.1.10
OR
xinexine-libMatch1.1.10.1
OR
xinexine-libMatch1.1.11
Node
xiphspeexRange≀1.1.12
OR
xiphspeexMatch1.0.2
OR
xiphspeexMatch1.0.3
OR
xiphspeexMatch1.0.4
OR
xiphspeexMatch1.0.5
OR
xiphspeexMatch1.1.1
OR
xiphspeexMatch1.1.2
OR
xiphspeexMatch1.1.3
OR
xiphspeexMatch1.1.4
OR
xiphspeexMatch1.1.5
OR
xiphspeexMatch1.1.6
OR
xiphspeexMatch1.1.7
OR
xiphspeexMatch1.1.8
OR
xiphspeexMatch1.1.9
OR
xiphspeexMatch1.1.10
OR
xiphspeexMatch1.1.11
OR
xiphspeexMatch1.1.11.1
AND
xiphlibfishsoundRange≀0.9.0
OR
xiphlibfishsoundMatch0.5.41
OR
xiphlibfishsoundMatch0.5.42
OR
xiphlibfishsoundMatch0.6.0
OR
xiphlibfishsoundMatch0.6.1
OR
xiphlibfishsoundMatch0.6.2
OR
xiphlibfishsoundMatch0.6.3
OR
xiphlibfishsoundMatch0.7.0
OR
xiphlibfishsoundMatch0.8.0
OR
xiphlibfishsoundMatch0.8.1

References

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.4 High

AI Score

Confidence

Low

0.068 Low

EPSS

Percentile

93.9%