CVE-2008-1881

VLC 0.8.6e - Buffer Overflow

Title source: llm

Description

Stack-based buffer overflow in the ParseSSA function (modules/demux/subtitle.c) in VLC 0.8.6e allows remote attackers to execute arbitrary code via a long subtitle in an SSA file. NOTE: this issue is due to an incomplete fix for CVE-2007-6681.

Exploits (2)

exploitdb WORKING POC VERIFIED
by j0rgan · pythonlocalwindows
https://www.exploit-db.com/exploits/5667
exploitdb WORKING POC VERIFIED
by Mai Xuan Cuong · c++localwindows
https://www.exploit-db.com/exploits/5250

Scores

EPSS 0.5399
EPSS Percentile 98.0%

Details

CWE
CWE-119
Status published
Products (1)
videolan/vlc 0.8.6e
Published Apr 17, 2008
Tracked Since Feb 18, 2026