CVE-2008-5259

Integer signedness error in DivX Web Player 1.4.2.7, and possibly earlier versions, allows remote attackers to execute arbitrary code via a DivX file containing a crafted Stream Format (STRF) chunk, which triggers a heap-based buffer overflow.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:C/I:C/A:C
flexeraCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 89%
VendorProductVersion
divxdivx_web_player
𝑥
≤ 1.4.2.7
divxdivx_web_player
1.0.1
divxdivx_web_player
1.0.2
divxdivx_web_player
1.1
divxdivx_web_player
1.1.0
divxdivx_web_player
1.2
divxdivx_web_player
1.2.0
divxdivx_web_player
1.3
divxdivx_web_player
1.3.0
divxdivx_web_player
1.3.1
divxdivx_web_player
1.4
divxdivx_web_player
1.4.0:beta2
divxdivx_web_player
1.4.1:beta1
divxdivx_web_player
1.4.2:beta2
𝑥
= Vulnerable software versions
Common Weakness Enumeration