CVE-2011-0500
high · 9.3Buffer overflow in VideoSpirit Pro 1.6.8.1, 1.68, and earlier; and VideoSpirit Lite 1.4.0.1 and possibly other versions; allows user-assisted remote attackers to execute arbitrary code via a VideoSpirit project (.visprj) file containing a valitem element with a long "value" attribute, as demonstrated using a valitem with the mp3 name.
9.3
CVSS
30.7%
EPSS (exploit prob.)
98th
EPSS percentile
2011-01-20
Published
AV:N/AC:M/Au:N/C:C/I:C/A:C
Weaknesses
CWE-119
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| verytools | videospirit_lite | 1.4.0.1 |
| verytools | videospirit_pro | <= 1.68 |
| verytools | videospirit_pro | 1.6.8.1 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2011-0500