9.3
CVSSv2

CVE-2007-4939

Published: 18/09/2007 Updated: 15/10/2018
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Heap-based buffer overflow in mplayerc.exe in Media Player Classic (MPC) 6.4.9.0 and previous versions, as used standalone and in mympc (aka CD-Storm) 1.0.0.1, StormPlayer 1.0.4, and possibly other products, allows remote malicious users to cause a denial of service (application crash) or possibly execute arbitrary code via a .avi file with an "indx truck size" of 0xffffffff, and certain wLongsPerEntry and nEntriesInuse values.

Vulnerable Product Search on Vulmon Subscribe to Product

mympc cd-storm 1.0.0.1

verycd stormplayer 1.0.4

guliverkli media player classic

Exploits

source: wwwsecurityfocuscom/bid/25650/info Media Player Classic (MPC) is prone to multiple remote vulnerabilities, including a heap-based buffer-overflow issue and an integer-overflow issue, when handling malformed AVI files An attacker can exploit these issues to execute arbitrary code with the privileges of the user running the affect ...