CVE-2011-0500

Verytools Videospirit Lite < 1.68 - Memory Corruption

Title source: rule

Description

Buffer overflow in VideoSpirit Pro 1.6.8.1, 1.68, and earlier; and VideoSpirit Lite 1.4.0.1 and possibly other versions; allows user-assisted remote attackers to execute arbitrary code via a VideoSpirit project (.visprj) file containing a valitem element with a long "value" attribute, as demonstrated using a valitem with the mp3 name.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubylocalwindows
https://www.exploit-db.com/exploits/17153
exploitdb WORKING POC VERIFIED
by xsploitedsec · pythonlocalwindows
https://www.exploit-db.com/exploits/15936

Scores

EPSS 0.6431
EPSS Percentile 98.5%

Details

CWE
CWE-119
Status published
Products (3)
verytools/videospirit_lite 1.4.0.1
verytools/videospirit_pro 1.6.8.1
verytools/videospirit_pro < 1.68
Published Jan 20, 2011
Tracked Since Feb 18, 2026