← back
CVE-2008-5036

CVE-2008-5036

50Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 41%
from disclosure to weapon1208 days
Published on NVDNov 10
1st PoC+1208d
metasploitNov 5
exploitation probability
41%top 1% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
Stack-based buffer overflow in VideoLAN VLC media player 0.9.x before 0.9.6 might allow user-assisted attackers to execute arbitrary code via an an invalid RealText (rt) subtitle file, related to the ParseRealText function in modules/demux/subtitle.c. NOTE: this issue was SPLIT from CVE-2008-5032 on 20081110.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.