9.3

CVE-2007-4940

Exploit
Multiple integer overflows in Media Player Classic (MPC) 6.4.9.0 and earlier, as used standalone and in mympc (aka CD-Storm) 1.0.0.1, StormPlayer 1.0.4, and possibly other products, allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a .avi file with certain large "indx truck size" and nEntriesInuse values.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
GuliverkliMedia Player Classic Version <= 6.4.9.0
MympcCd-storm Version1.0.0.1
VerycdStormplayer Version1.0.4
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.37% 0.9
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://securityreason.com/securityalert/3144
http://www.securityfocus.com/archive/1/479222/100/0/threaded
http://www.vulnhunt.com/advisories/CAL-20070912-1_Multiple_vendor_produce_handling_AVI_file_vulnerabilities.txt
Exploit
http://www.securityfocus.com/bid/25650
https://exchange.xforce.ibmcloud.com/vulnerabilities/36584