CVE-2008-4654

Videolan Vlc Media Player - Memory Corruption

Title source: rule

Description

Stack-based buffer overflow in the parse_master function in the Ty demux plugin (modules/demux/ty.c) in VLC Media Player 0.9.0 through 0.9.4 allows remote attackers to execute arbitrary code via a TiVo TY media file with a header containing a crafted size value.

Exploits (8)

nomisec WORKING POC 2 stars
by KernelErr · poc
https://github.com/KernelErr/VLC-CVE-2008-4654-Exploit
nomisec WORKING POC
by rnnsz · poc
https://github.com/rnnsz/CVE-2008-4654
nomisec WORKING POC
by Hexastrike · poc
https://github.com/Hexastrike/CVE-2008-4654
nomisec WORKING POC
by bongbongco · poc
https://github.com/bongbongco/CVE-2008-4654
metasploit WORKING POC GOOD
rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/fileformat/videolan_tivo.rb
exploitdb WORKING POC
perllocalwindows
https://www.exploit-db.com/exploits/6825
exploitdb WORKING POC VERIFIED
by Metasploit · rubylocalwindows
https://www.exploit-db.com/exploits/16629
exploitdb WORKING POC
perllocalwindows
https://www.exploit-db.com/exploits/6798

Scores

EPSS 0.7462
EPSS Percentile 98.8%

Classification

CWE
CWE-119
Status draft

Affected Products (5)

videolan/vlc_media_player
videolan/vlc_media_player
videolan/vlc_media_player
videolan/vlc_media_player
videolan/vlc_media_player

Timeline

Published Oct 22, 2008
Tracked Since Feb 18, 2026