10
CVSSv2

CVE-2009-4637

Published: 10/02/2010 Updated: 20/05/2010
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

FFmpeg 0.5 allows remote malicious users to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors that trigger a stack-based buffer overflow.

Vulnerable Product Search on Vulmon Subscribe to Product

ffmpeg ffmpeg 0.5

Vendor Advisories

It was discovered that FFmpeg contained multiple security issues when handling certain multimedia files If a user were tricked into opening a crafted multimedia file, an attacker could cause a denial of service via application crash, or possibly execute arbitrary code with the privileges of the user invoking the program ...
Several vulnerabilities have been discovered in ffmpeg, a multimedia player, server and encoder, which also provides a range of multimedia libraries used in applications like MPlayer: Various programming errors in container and codec implementations may lead to denial of service or the execution of arbitrary code if the user is tricked into opening ...

Exploits

source: wwwsecurityfocuscom/bid/36465/info FFmpeg is prone to multiple remote vulnerabilities Attackers may leverage these issues to execute arbitrary code in the context of the application or crash the application FFmpeg 05 is affected; other versions may also be vulnerable githubcom/offensive-security/exploitdb-bin-sploi ...