Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2009-0894

EPSS 4.31% · P89
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2009-0894

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Heap-based buffer overflow in the decoder_create function in the initialization functionality in xvidcore/src/decoder.c in Xvid before 1.2.2, as used by Windows Media Player and other applications, allows remote attackers to execute arbitrary code via vectors involving the DirectShow (aka DShow) frontend and improper handling of the XVID_ERR_MEMORY return code during processing of a crafted movie file. NOTE: some of these details are obtained from third party information.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Xvid视频解码器DirectShow初始化逻辑堆溢出漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Xvid是一款流行的视频解码器。 Xvid视频解码器的DirectShow组件在处理初始化失败情况时存在逻辑错误,在创建贴图管线中的某个点如果出现了内存分配错误的话,就会使用错误的返回值,这最终允许攻击者使用指向了无效或已释放内存的数据结构继续解码视频。成功利用这个漏洞的攻击者可以触发堆溢出,导致执行任意代码。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2009-0894

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2009-0894

登录查看更多情报信息。

Same Patch Batch · n/a · 2009-06-02 · 16 CVEs total

CVE-2009-0185Apple QuickTime Player 解码"MS ADPCM" 堆缓冲区溢出漏洞
CVE-2009-0188Apple QuickTime Player 视频文件"Sorenson 3" 内存破坏漏洞
CVE-2009-0893xvidcore library安全漏洞
CVE-2009-0950Apple iTunes多个URI处理器栈溢出漏洞
CVE-2009-0951Apple QuickTime Player 文件"FLC" 堆缓冲区溢出漏洞
CVE-2009-0952Apple QuickTime Player 图片"PSD" 缓冲区溢出漏洞
CVE-2009-0953Apple QuickTime Player 图片"PICT" 堆缓冲区溢出漏洞
CVE-2009-0954Apple QuickTime Player "CRGN原子类型" 堆缓冲区溢出漏洞
CVE-2009-0955Apple QuickTime Player 视频文件"Apple" 堆缓冲区溢出漏洞
CVE-2009-0956Apple QuickTime Player 视频文件"用户数据原子" 内存错误漏洞
CVE-2009-0957Apple QuickTime Player 图片"JP2" 堆缓冲区溢出漏洞
CVE-2009-1880MT312 REP-BBS 多个跨站脚本攻击漏洞
CVE-2009-1881MT312 IMG-BBS "model.php" 跨站脚本攻击漏洞
CVE-2009-1882ImageMagick TIFF文件解析整数溢出漏洞
CVE-2004-2764Sun Java Runtime Environment Remote XSLT特权升级漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2009-0894

No comments yet


Leave a comment