Show filters
187 Total Results
Displaying 51-60 of 187
Sort by:
Attacker Value
Unknown

CVE-2010-2745

Disclosure Date: October 13, 2010 (last updated October 04, 2023)
Microsoft Windows Media Player (WMP) 9 through 12 does not properly deallocate objects during a browser reload action, which allows user-assisted remote attackers to execute arbitrary code via crafted media content referenced in an HTML document, aka "Windows Media Player Memory Corruption Vulnerability."
0
Attacker Value
Unknown

CVE-2010-3138

Disclosure Date: August 27, 2010 (last updated October 04, 2023)
Untrusted search path vulnerability in the Indeo Codec in iac25_32.ax in Microsoft Windows XP SP3 allows local users to gain privileges via a Trojan horse iacenc.dll file in the current working directory, as demonstrated by access through BS.Player or Media Player Classic to a directory that contains a .avi, .mka, .ra, or .ram file, aka "Indeo Codec Insecure Library Loading Vulnerability." NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2010-1879

Disclosure Date: June 08, 2010 (last updated October 04, 2023)
Unspecified vulnerability in Quartz.dll for DirectShow; Windows Media Format Runtime 9, 9.5, and 11; Media Encoder 9; and the Asycfilt.dll COM component allows remote attackers to execute arbitrary code via a media file with crafted compression data, aka "Media Decompression Vulnerability."
0
Attacker Value
Unknown

CVE-2010-0268

Disclosure Date: April 14, 2010 (last updated October 04, 2023)
Unspecified vulnerability in the Windows Media Player ActiveX control in Windows Media Player (WMP) 9 on Microsoft Windows 2000 SP4 and XP SP2 and SP3 allows remote attackers to execute arbitrary code via crafted media content, aka "Media Player Remote Code Execution Vulnerability."
0
Attacker Value
Unknown

CVE-2010-1042

Disclosure Date: March 23, 2010 (last updated October 04, 2023)
Microsoft Windows Media Player 11 does not properly perform colorspace conversion, which allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted .AVI file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown

CVE-2010-0718

Disclosure Date: February 26, 2010 (last updated October 04, 2023)
Buffer overflow in Microsoft Windows Media Player 9 and 11.0.5721.5145 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted .mpg file.
0
Attacker Value
Unknown

CVE-2010-0278

Disclosure Date: January 12, 2010 (last updated October 04, 2023)
A certain ActiveX control in msgsc.14.0.8089.726.dll in Microsoft Windows Live Messenger 2009 build 14.0.8089.726 on Windows Vista and Windows 7 allows remote attackers to cause a denial of service (msnmsgr.exe crash) by calling the ViewProfile method with a crafted argument during an MSN Messenger session.
0
Attacker Value
Unknown

CVE-2009-4310

Disclosure Date: December 13, 2009 (last updated October 04, 2023)
Stack-based buffer overflow in the Intel Indeo41 codec for Windows Media Player in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via crafted compressed video data in an IV41 stream in a media file, leading to many loop iterations, as demonstrated by data in an AVI file.
0
Attacker Value
Unknown

CVE-2009-4309

Disclosure Date: December 13, 2009 (last updated October 04, 2023)
Heap-based buffer overflow in the Intel Indeo41 codec for Windows Media Player in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via a large size value in a movi record in an IV41 stream in a media file, as demonstrated by an AVI file.
0
Attacker Value
Unknown

CVE-2009-2527

Disclosure Date: October 14, 2009 (last updated October 04, 2023)
Heap-based buffer overflow in Microsoft Windows Media Player 6.4 allows remote attackers to execute arbitrary code via (1) a crafted ASF file or (2) crafted streaming content, aka "WMP Heap Overflow Vulnerability."
0