CVE-2007-6683

Advisory lineage Upstream: 0 Downstream: 3
Modified
Published: 17 Jan 2008, 00:00
Last modified:07 Aug 2024, 16:18

Vulnerability Summary

Overall Risk (default)
medium
30/100
CVSS Score
5 MEDIUM
v2.0 (nvd)
EPSS Score
0.9% LOW
1% probability +0.16%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

17 Jan 2008, 00:00
Published
Vulnerability first disclosed
07 Aug 2024, 16:18
Last Modified
Vulnerability information updated

Description

The browser plugin in VideoLAN VLC 0.8.6d allows remote attackers to overwrite arbitrary files via (1) the :demuxdump-file option in a filename in a playlist, or (2) a EXTVLCOPT statement in an MP3 file, possibly an argument injection vulnerability.

CVSS Metrics

  • v2.0MEDIUMScore: 5AV:N/AC:L/Au:N/C:N/I:P/A:N

EPSS Trends

Current EPSS score: 0.90% Percentile: 76%

Affected Systems

  • videolanvlc

    0.8.6d

References (11)