Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2010-0480 | First vendor Publication | 2010-04-14 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:N/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 9.3 | Attack Range | Network |
Cvss Impact Score | 10 | Attack Complexity | Medium |
Cvss Expoit Score | 8.6 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Multiple stack-based buffer overflows in the MPEG Layer-3 audio codecs in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allow remote attackers to execute arbitrary code via a crafted AVI file, aka "MPEG Layer-3 Audio Decoder Stack Overflow Vulnerability." |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0480 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-119 | Failure to Constrain Operations within the Bounds of a Memory Buffer |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:7441 | |||
Oval ID: | oval:org.mitre.oval:def:7441 | ||
Title: | MPEG Layer-3 Audio Decoder Stack Overflow Vulnerability | ||
Description: | Multiple stack-based buffer overflows in the MPEG Layer-3 audio codecs in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allow remote attackers to execute arbitrary code via a crafted AVI file, aka "MPEG Layer-3 Audio Decoder Stack Overflow Vulnerability." | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2010-0480 | Version: | 3 |
Platform(s): | Microsoft Windows XP Microsoft Windows Vista Microsoft Windows Server 2003 Microsoft Windows Server 2008 | Product(s): | |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
ExploitDB Exploits
id | Description |
---|---|
2011-08-13 | MS10-026 Microsoft MPEG Layer-3 Audio Stack Based Overflow |
2010-09-05 | MOAUB #5 - Microsoft MPEG Layer-3 Remote Command Execution Exploit |
OpenVAS Exploits
Date | Description |
---|---|
2010-04-14 | Name : Microsoft Windows Media Services Remote Code Execution Vulnerability (980858) File : nvt/secpod_ms10-025.nasl |
2010-04-14 | Name : Microsoft MPEG Layer-3 Codecs Remote Code Execution Vulnerability (977816) File : nvt/secpod_ms10-026.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
63749 | Microsoft Windows MPEG Layer-3 Audio Decoder AVI File Handling Overflow |
Information Assurance Vulnerability Management (IAVM)
Date | Description |
---|---|
2010-04-15 | IAVM : 2010-A-0053 - Microsoft MPEG Layer-3 Codecs Remote Code Execution Vulnerability Severity : Category II - VMSKEY : V0023999 |
Snort® IPS/IDS
Date | Description |
---|---|
2014-01-10 | Microsoft Windows Media Player codec code execution attempt RuleID : 16543 - Revision : 16 - Type : FILE-MULTIMEDIA |
Metasploit Database
id | Description |
---|---|
2010-04-13 | MS10-026 Microsoft MPEG Layer-3 Audio Stack Based Overflow |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2010-04-13 | Name : An audio codec on the remote Windows host has a buffer overflow vulnerability. File : smb_nt_ms10-026.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:08:47 |
|
2024-11-28 12:21:08 |
|
2023-12-07 21:28:04 |
|
2021-05-04 12:11:04 |
|
2021-04-22 01:11:40 |
|
2020-05-23 13:16:54 |
|
2020-05-23 00:25:15 |
|
2019-02-26 17:19:32 |
|
2018-10-31 00:20:02 |
|
2018-10-13 00:22:54 |
|
2017-09-19 09:23:38 |
|
2016-09-30 01:02:19 |
|
2016-08-31 12:02:03 |
|
2016-04-26 19:34:09 |
|
2014-02-17 10:53:45 |
|
2014-01-19 21:26:37 |
|
2013-11-11 12:38:38 |
|
2013-05-10 23:17:42 |
|