Vulnerability Name: | CVE-2009-0910 (CCN-49704) | ||||||||
Assigned: | 2009-04-03 | ||||||||
Published: | 2009-04-03 | ||||||||
Updated: | 2017-09-29 | ||||||||
Summary: | Heap-based buffer overflow in the VNnc Codec in VMware Workstation 6.5.x before 6.5.2 build 156735, VMware Player 2.5.x before 2.5.2 build 156735, VMware ACE 2.5.x before 2.5.2 build 156735, and VMware Server 2.0.x before 2.0.1 build 156745 allows remote attackers to execute arbitrary code via a crafted web page or video file, aka ZDI-CAN-436. | ||||||||
CVSS v3 Severity: | 10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P) 5.0 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
6.9 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-119 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2009-0910 Source: CCN Type: TPTI-09-02 VMWare VMnc Codec Open-DML Standard Index dwSize Heap Overflow Vulnerability Source: MLIST Type: Patch, Vendor Advisory [security-announce] 20090403 VMSA-2009-0005 VMware Hosted products, VI Client and patches for ESX and ESXi resolve multiple security issues Source: FULLDISC Type: Patch 20090403 VMSA-2009-0005 VMware Hosted products, VI Client and patches for ESX and ESXi resolve multiple security issues Source: GENTOO Type: UNKNOWN GLSA-201209-25 Source: CCN Type: SECTRACK ID: 1021974 VMware Heap Overflows in VNnc Codec Lets Remote Users Execute Arbitrary Code Source: CCN Type: OSVDB ID: 55942 VMWare Multiple Products VMnc Codec (vmnc.dll) Open-DML Standard Index dwSize Element Handling Overflow Source: BID Type: Exploit 34373 Source: CCN Type: BID-34373 VMware Hosted Products VMSA-2009-0005 Multiple Remote Vulnerabilities Source: SECTRACK Type: UNKNOWN 1021974 Source: CCN Type: VMSA-2009-0005 VMware Hosted products, VI Client and patches for ESX and ESXi resolve multiple security issues Source: CONFIRM Type: UNKNOWN http://www.vmware.com/security/advisories/VMSA-2009-0005.html Source: VUPEN Type: UNKNOWN ADV-2009-0944 Source: XF Type: UNKNOWN vmware-vnnc-dwsize-bo(49704) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:5786 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |