CVE-2009-4637

FFmpeg 0.5 - Stack-based Buffer Overflow

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2009-4637. PoCs published by Will Dormann.

AI-analyzed exploit summary The provided text describes multiple remote vulnerabilities in FFmpeg 0.5, potentially leading to arbitrary code execution or application crashes. It references external binaries but does not contain actual exploit code.

Description

FFmpeg 0.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors that trigger a stack-based buffer overflow.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Will Dormann · textdoslinux
https://www.exploit-db.com/exploits/33233

The provided text describes multiple remote vulnerabilities in FFmpeg 0.5, potentially leading to arbitrary code execution or application crashes. It references external binaries but does not contain actual exploit code.

Classification
Writeup 90%
Attack Type
Rce | Dos
Complexity
Theoretical
Reliability
Theoretical
Target: FFmpeg 0.5
No auth needed
Prerequisites: Access to a vulnerable FFmpeg installation
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (9)

Core 9
Core References
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/36805
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/36465
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/39482
Various Sources x_refsource_misc
https://roundup.ffmpeg.org/roundup/ffmpeg/issue1240
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/38643
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2010/dsa-2000
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-931-1
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2010/0935

Scores

EPSS 0.1691
EPSS Percentile 96.7%

Details

CWE
CWE-119
Status published
Products (1)
ffmpeg/ffmpeg 0.5
Published Feb 10, 2010
Tracked Since Feb 18, 2026