Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2009-0199 | First vendor Publication | 2009-09-08 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:N/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 9.3 | Attack Range | Network |
Cvss Impact Score | 10 | Attack Complexity | Medium |
Cvss Expoit Score | 8.6 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Heap-based buffer overflow in the VMnc media codec in vmnc.dll in VMware Movie Decoder before 6.5.3 build 185404, VMware Workstation 6.5.x before 6.5.3 build 185404, VMware Player 2.5.x before 2.5.3 build 185404, and VMware ACE 2.5.x before 2.5.3 build 185404 on Windows might allow remote attackers to execute arbitrary code via a video file with crafted dimensions (aka framebuffer parameters). |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0199 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-119 | Failure to Constrain Operations within the Bounds of a Memory Buffer |
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Application | 3 | |
Application | 1 | |
Application | 4 | |
Application | 4 |
OpenVAS Exploits
Date | Description |
---|---|
2009-09-16 | Name : VMware Products Multiple Vulnerabilities (Win) sep09 File : nvt/secpod_vmware_prdts_mult_vuln_win_sep09.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
57835 | VMware Workstation Movie Decoder VMnc Codec (vmnc.dll) Crafted Video File Han... |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2014-11-26 | Name : The remote OracleVM host is missing a security update. File : oraclevm_OVMSA-2009-0012.nasl - Type : ACT_GATHER_INFO |
2009-09-09 | Name : The remote host contains an application that is affected by multiple heap ove... File : vmware_vmnc_codec_653.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:10:26 |
|
2024-11-28 12:18:07 |
|
2021-05-04 12:09:02 |
|
2021-04-22 01:09:22 |
|
2020-05-23 00:23:14 |
|
2018-10-12 00:20:35 |
|
2016-04-26 18:34:09 |
|
2014-02-17 10:48:27 |
|
2013-05-10 23:42:42 |
|