9.3
CVE-2007-4940
- EPSS 4.37%
- Veröffentlicht 18.09.2007 19:17:00
- Zuletzt bearbeitet 16.06.2026 22:45:07
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Multiple integer overflows in Media Player Classic (MPC) 6.4.9.0 and earlier, as used standalone and in mympc (aka CD-Storm) 1.0.0.1, StormPlayer 1.0.4, and possibly other products, allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a .avi file with certain large "indx truck size" and nEntriesInuse values.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Guliverkli ≫ Media Player Classic Version <= 6.4.9.0
Verycd ≫ Stormplayer Version1.0.4
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 4.37% | 0.9 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.3 | 8.6 | 10 |
AV:N/AC:M/Au:N/C:C/I:C/A:C
|
http://securityreason.com/securityalert/3144
http://www.securityfocus.com/archive/1/479222/100/0/threaded
http://www.vulnhunt.com/advisories/CAL-20070912-1_Multiple_vendor_produce_handling_AVI_file_vulnerabilities.txt
http://www.securityfocus.com/bid/25650
https://exchange.xforce.ibmcloud.com/vulnerabilities/36584