CVE-2008-4686 EXPLOIT
9.3
HIGH · CVSS 2.0 · EPSS 9.9% (pctl 95)
Patch early
A public exploit exists.
Description
Multiple integer overflows in ty.c in the TY demux plugin (aka the TiVo demuxer) in VideoLAN VLC media player, probably 0.9.4, might allow remote attackers to execute arbitrary code via a crafted .ty file, a different vulnerability than CVE-2008-4654.
Scoring
| CVSS | 9.3 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
| EPSS | 9.94% — more likely to be exploited than 95% of all CVEs |
| Weakness | CWE-189 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2008-10-22 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| videolan | vlc media player |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | VideoLAN VLC Media Player 0.9.4 - '.ty' Local Buffer Overflow (SEH) | 2008-10-23 |
| exploit-db | VideoLAN VLC Media Player 0.9.4 - '.TY' Local Stack Buffer Overflow | 2008-10-21 |
References
- http://git.videolan.org/?p=vlc.git%3Ba=commitdiff%3Bh=d859e6b9537af2d7326276f70de25a840f554dc3
- http://www.openwall.com/lists/oss-security/2008/10/19/2
- http://www.openwall.com/lists/oss-security/2008/10/22/6
- http://www.securityfocus.com/bid/31867
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14630
- http://git.videolan.org/?p=vlc.git%3Ba=commitdiff%3Bh=d859e6b9537af2d7326276f70de25a840f554dc3
- http://www.openwall.com/lists/oss-security/2008/10/19/2
- http://www.openwall.com/lists/oss-security/2008/10/22/6
- http://www.securityfocus.com/bid/31867
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14630
→ the Explorer · watch your stack · NVD