CVE-2008-1881
VLC 0.8.6e - Buffer Overflow
Title source: llmDescription
Stack-based buffer overflow in the ParseSSA function (modules/demux/subtitle.c) in VLC 0.8.6e allows remote attackers to execute arbitrary code via a long subtitle in an SSA file. NOTE: this issue is due to an incomplete fix for CVE-2007-6681.
Exploits (2)
exploitdb
WORKING POC
VERIFIED
by j0rgan · pythonlocalwindows
https://www.exploit-db.com/exploits/5667
exploitdb
WORKING POC
VERIFIED
by Mai Xuan Cuong · c++localwindows
https://www.exploit-db.com/exploits/5250
References (13)
Scores
EPSS
0.5399
EPSS Percentile
98.0%
Details
CWE
CWE-119
Status
published
Products (1)
videolan/vlc
0.8.6e
Published
Apr 17, 2008
Tracked Since
Feb 18, 2026