7.6

CVE-2007-4938

Exploit

Heap-based buffer overflow in libmpdemux/aviheader.c in MPlayer 1.0rc1 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a .avi file with certain large "indx truck size" and nEntriesInuse values, and a certain wLongsPerEntry value.

Data is provided by the National Vulnerability Database (NVD)
MplayerMplayer Version1.0_rc1
   ApplemacOS X
   HpHp-ux
   HpTru64
   IbmAix
   IbmOs2
   LinuxLinux Kernel
   MandrakesoftMandrake Linux Version2007
   MandrakesoftMandrake Linux Version2007 Editionx86_64
   MandrakesoftMandrake Linux Version2007.1
   MandrakesoftMandrake Linux Version2007.1 Editionx86_64
   MicrosoftWindows 2000
   MicrosoftWindows 2003 Server
   MicrosoftWindows 98
   MicrosoftWindows Me
   MicrosoftWindows Nt Version4.0
   MicrosoftWindows Xp
   Santa Cruz OperationSco Unix
   SunSolaris
   WindriverBsdos
SgiIrix
   ApplemacOS X
   HpHp-ux
   HpTru64
   IbmAix
   IbmOs2
   LinuxLinux Kernel
   MandrakesoftMandrake Linux Version2007
   MandrakesoftMandrake Linux Version2007 Editionx86_64
   MandrakesoftMandrake Linux Version2007.1
   MandrakesoftMandrake Linux Version2007.1 Editionx86_64
   MicrosoftWindows 2000
   MicrosoftWindows 2003 Server
   MicrosoftWindows 98
   MicrosoftWindows Me
   MicrosoftWindows Nt Version4.0
   MicrosoftWindows Xp
   Santa Cruz OperationSco Unix
   SunSolaris
   WindriverBsdos
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 6.38% 0.907
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.6 4.9 10
AV:N/AC:H/Au:N/C:C/I:C/A:C
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.