Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2009-2628 | First vendor Publication | 2009-09-08 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:N/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 9.3 | Attack Range | Network |
Cvss Impact Score | 10 | Attack Complexity | Medium |
Cvss Expoit Score | 8.6 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
The VMnc media codec in vmnc.dll in VMware Movie Decoder before 6.5.3 build 185404, VMware Workstation 6.5.x before 6.5.3 build 185404, VMware Player 2.5.x before 2.5.3 build 185404, and VMware ACE 2.5.x before 2.5.3 build 185404 on Windows does not properly handle certain small heights in video content, which might allow remote attackers to execute arbitrary code via a crafted AVI file that triggers heap memory corruption. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2628 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-94 | Failure to Control Generation of Code ('Code Injection') |
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Application | 3 | |
Application | 1 | |
Application | 3 | |
Application | 4 |
OpenVAS Exploits
Date | Description |
---|---|
2009-09-16 | Name : VMware Products Multiple Vulnerabilities (Win) sep09 File : nvt/secpod_vmware_prdts_mult_vuln_win_sep09.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
57836 | VMware Workstation Movie Decoder VMnc Codec (vmnc.dll) Crafted AVI File Handl... |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2014-11-26 | Name : The remote OracleVM host is missing a security update. File : oraclevm_OVMSA-2009-0012.nasl - Type : ACT_GATHER_INFO |
2009-09-09 | Name : The remote host contains an application that is affected by multiple heap ove... File : vmware_vmnc_codec_653.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:10:26 |
|
2024-11-28 12:19:29 |
|
2021-05-04 12:09:52 |
|
2021-04-22 01:10:13 |
|
2020-05-23 00:24:05 |
|
2018-10-11 00:19:39 |
|
2016-04-26 19:00:13 |
|
2014-02-17 10:50:57 |
|
2013-05-10 23:54:40 |
|