peter bassill · operator
$ cve CVE-2008-0984 JSON

CVE-2008-0984 EXPLOIT

9.3
HIGH · CVSS 2.0 · EPSS 15.3% (pctl 97)

Patch early

A public exploit exists.

Description

The MP4 demuxer (mp4.c) for VLC media player 0.8.6d and earlier, as used in Miro Player 1.1 and earlier, allows remote attackers to overwrite arbitrary memory and execute arbitrary code via a malformed MP4 file.

Scoring

CVSS9.3 (HIGH, v2.0)
VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS15.28% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-399
On CISA KEVno
Public exploityes
Published2008-02-26
Last modified2026-06-16

Affected (2)

VendorProduct
miromiro player
videolanvlc media player

Public exploits

SourceTitleDate
exploit-dbKantaris 0.3.4 - SSA Subtitle Local Buffer Overflow2008-04-25

References

→ the Explorer  ·  watch your stack  ·  NVD