cbcvebase.
CVE-2008-4201
published 2008-09-24

CVE-2008-4201: Heap-based buffer overflow in the decodeMP4file function (frontend/main.c) in FAAD2 2.6.1 and earlier allows remote attackers to cause a denial of service…

PriorityP340critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
6.65%
93.1th percentile
Heap-based buffer overflow in the decodeMP4file function (frontend/main.c) in FAAD2 2.6.1 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted MPEG-4 (MP4) file.

Affected

9 ranges
VendorProductVersion rangeFixed in
audiocodingfaad2<= 2.6.1
audiocodingfaad2
audiocodingfaad2
audiocodingfaad2
debianfaad2< faad2 2.6.1-3.1 (bookworm)faad2 2.6.1-3.1 (bookworm)
faad2_projectfaad2>= 0 < 2.6.1-3.12.6.1-3.1
faad2_projectfaad2>= 0 < 2.6.1-3.12.6.1-3.1
faad2_projectfaad2>= 0 < 2.6.1-3.12.6.1-3.1
faad2_projectfaad2>= 0 < 2.6.1-3.12.6.1-3.1

CVSS provenance

nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
vendor_debian9.3CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.