CVE-2010-3907

Advisory lineage Upstream: 0 Downstream: 2
Modified
Published: 03 Jan 2011, 19:26
Last modified:07 Aug 2024, 03:26

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
9.3 HIGH
v2.0 (nvd)
EPSS Score
2.76% LOW
3% probability -1.99%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

03 Jan 2011, 19:26
Published
Vulnerability first disclosed
07 Aug 2024, 03:26
Last Modified
Vulnerability information updated

Description

Multiple integer overflows in real.c in the Real demuxer plugin in VideoLAN VLC Media Player before 1.1.6 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a zero i_subpackets value in a Real Media file, leading to a heap-based buffer overflow.

CVSS Metrics

  • v2.0HIGHScore: 9.3AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS Trends

Current EPSS score: 2.76% Percentile: 86%

Techniques & Countermeasures

  • CWE-189Numeric Errors

    Weaknesses in this category are related to improper calculation or conversion of numbers.

Affected Systems

  • videolanvlc_media_player

    ≤ 1.1.5 | 0.1.99b | 0.1.99e | 0.1.99f | 0.1.99g | 0.1.99h | 0.1.99i | 0.2.0 | 0.2.60 | 0.2.61 | 0.2.62 | 0.2.63 | 0.2.70 | 0.2.71 | 0.2.72 | 0.2.73 | 0.2.80 | 0.2.81 | 0.2.82 | 0.2.83 | 0.2.90 | 0.2.91 | 0.2.92 | 0.3.0 | 0.3.1 | 0.4.0 | 0.4.1 | 0.4.2 | 0.4.3 | 0.4.4 | 0.4.5 | 0.4.6 | 0.5.0 | 0.5.1 | 0.5.2 | 0.5.3 | 0.6.0 | 0.6.1 | 0.6.2 | 0.7.0 | 0.7.2 | 0.8.0 | 0.8.1 | 0.8.2 | 0.8.4 | 0.8.5 | 0.8.6 | 0.9.2 | 0.9.3 | 0.9.4 | 0.9.5 | 0.9.6 | 0.9.8a | 0.9.9 | 0.9.10 | 1.0.0 | 1.0.1 | 1.0.2 | 1.0.3 | 1.0.4 | 1.0.5 | 1.0.6 | 1.1.0 | 1.1.1 | 1.1.2 | 1.1.3 | 1.1.4

References (7)