← All CVEs

CVE-2007-4938

high · 7.6

Heap-based buffer overflow in libmpdemux/aviheader.c in MPlayer 1.0rc1 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a .avi file with certain large "indx truck size" and nEntriesInuse values, and a certain wLongsPerEntry value.

7.6
CVSS
16.0%
EPSS (exploit prob.)
97th
EPSS percentile
2007-09-18
Published

AV:N/AC:H/Au:N/C:C/I:C/A:C

Weaknesses

CWE-119

Affected products

VendorProductAffected versions
applemac_os_xall versions
hphp-uxall versions
hptru64all versions
ibmaixall versions
ibmos2all versions
linuxlinux_kernelall versions
mandrakesoftmandrake_linux2007
mandrakesoftmandrake_linux2007
mandrakesoftmandrake_linux2007.1
mandrakesoftmandrake_linux2007.1
microsoftwindows_2000all versions
microsoftwindows_2003_serverall versions
microsoftwindows_98all versions
microsoftwindows_meall versions
microsoftwindows_nt4.0
microsoftwindows_xpall versions
santa_cruz_operationsco_unixall versions
sunsolarisall versions
windriverbsdosall versions
mplayermplayer1.0_rc1
sgiirixall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2007-4938