CVE-2009-0199

CWE-119Buffer Overflow3 documents3 sources
Severity
9.3CRITICAL
EPSS
12.0%
top 6.22%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 8
Latest updateMay 2

Description

Heap-based buffer overflow in the VMnc media codec in vmnc.dll in VMware Movie Decoder before 6.5.3 build 185404, VMware Workstation 6.5.x before 6.5.3 build 185404, VMware Player 2.5.x before 2.5.3 build 185404, and VMware ACE 2.5.x before 2.5.3 build 185404 on Windows might allow remote attackers to execute arbitrary code via a video file with crafted dimensions (aka framebuffer parameters).

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages4 packages

NVDvmware/player4 versions+3
NVDvmware/workstation4 versions+3
NVDvmware/ace2.5.0, 2.5.1, 2.5.2+2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-jqhc-vmcp-q22q: Heap-based buffer overflow in the VMnc media codec in vmnc2022-05-02
CVEList
CVE-2009-0199: Heap-based buffer overflow in the VMnc media codec in vmnc2009-09-08
CVE-2009-0199 (CRITICAL CVSS 9.3) | Heap-based buffer overflow in the V | cvebase.io