Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2009-1045Improper Input Validation in VLC Media Player

Severity
5.0MEDIUMNVD
EPSS
10.0%
top 6.94%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedMar 23
Latest updateMay 2

Description

requests/status.xml in VLC 0.9.8a allows remote attackers to cause a denial of service (stack consumption and crash) via a long input argument in an in_play action.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

🔴Vulnerability Details

3
GHSA
GHSA-p5jq-cw39-ccgj: requests/status2022-05-02
OSV
CVE-2009-1045: requests/status2009-03-23
CVEList
CVE-2009-1045: requests/status2009-03-23

💥Exploits & PoCs

1
Exploit-DB
VideoLAN VLC Media Player 0.9.8a - Web UI 'input' Remote Denial of Service2009-03-16

📋Vendor Advisories

1
Debian
CVE-2009-1045: vlc - requests/status.xml in VLC 0.9.8a allows remote attackers to cause a denial of s...2009
CVE-2009-1045 — Improper Input Validation | cvebase