1 results (0.003 seconds)

CVSS: 9.3EPSS: 5%CPEs: 14EXPL: 0

16 Apr 2009 — Integer signedness error in DivX Web Player 1.4.2.7, and possibly earlier versions, allows remote attackers to execute arbitrary code via a DivX file containing a crafted Stream Format (STRF) chunk, which triggers a heap-based buffer overflow. Error de presencia de signo entero en DivX Web Player v1.4.2.7, y posiblemente versiones anteriores, permite a atacantes remotos ejecutar código de su elección mediante un fichero DivX que contenga una porción Stream Format (STRF) manipulada, lo que dispara un desbord... • http://secunia.com/advisories/33196 • CWE-189: Numeric Errors •