← back
CVE-2009-2484

CVE-2009-2484

50Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 35%
from disclosure to weapon0 days
Published on NVDJul 16
1st PoCJun 29
metasploitJun 24
exploitation probability
35%top 2% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
Stack-based buffer overflow in the Win32AddConnection function in modules/access/smb.c in VideoLAN VLC media player 0.9.9, when running on Microsoft Windows, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long smb URI in a playlist file.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.