CVE-2008-4654
Stack-based buffer overflow in the parse_master function in the Ty demux plugin (modules/demux/ty.c) in VLC Media Player 0.9.0 through 0.9.4 allows remote...
- Published
- Oct 21, 2008
- Updated
- Aug 7, 2024
- Assigning CNA
- mitre
- Evidence observed
- Oct 21, 2008
Primary CVSS
nvd · CVSS 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:CHigh · next 30 days
- Percentile
- 99.1%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
Stack-based buffer overflow in the parse_master function in the Ty demux plugin (modules/demux/ty.c) in VLC Media Player 0.9.0 through 0.9.4 allows remote attackers to execute arbitrary code via a TiVo TY media file with a header containing a crafted size value.
Sources
7- CVE-2008-4654Exploit
VideoLAN VLC media player 0.9.4 Media Player ty.c buffer overflow
- CVE-2008-4654Exploit
A fully functional exploit for a stack-based buffer overflow vulnerability in VideoLan’s VLC Media Player 0.9.4 when processing TiVo files.
- VLC-CVE-2008-4654-ExploitExploit
An EXP could run on Windows x64 against CVE-2008-4654.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.