PoC Index

CVE-2007-6262

MEDIUM 6.8EPSS 11.1%

A certain ActiveX control in axvlc.dll in VideoLAN VLC 0.8.6 before 0.8.6d allows remote attackers to execute arbitrary code via crafted arguments to the (1) addTarget, (2) getVariable, or (3) setVariable function, resulting from a "bad initialized pointer," aka a "recursive plugin release vulnerability."

CVSS v2.0
6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS
11.12% chance of exploitation in the next 30 days, 96th percentile
Published
2007-12-06
Updated
2024-08-07

ExploitDB entries (1)

References

Related