V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2008-5745
CVE
MediumConfirmedExploit available

Integer overflow in quartz.dll in the DirectShow framework in Microsoft Windows Media Player (WMP) 9, 10, and 11, including 11.0.5721.5260,…

CVSS
4.3
Medium
EPSS
0.21
p97
Published
2008-01-01
Updated
2008-01-01
Description

Integer overflow in quartz.dll in the DirectShow framework in Microsoft Windows Media Player (WMP) 9, 10, and 11, including 11.0.5721.5260, allows remote attackers to cause a denial of service (application crash) via a crafted (1) WAV, (2) SND, or (3) MID file. NOTE: this has been incorrectly reported as a code-execution vulnerability. NOTE: it is not clear whether this issue is related to CVE-2008-4927.

Tags · CWE
CWE-189
Affected products
Windows_media_player
CVSS vector
AV:N/AC:M/Au:N/C:N/I:N/A:P
Timeline
2008-01-01
Published
2008-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: M
Medium
Authentication
Au: N
None (N)
Confidentiality Impact
C: N
None (N)
Integrity Impact
I: N
None (N)
Availability Impact
A: P
Partial
Exploit indicators
EPSS
0.214 · p97
Known exploited (KEV)
No
Known exploits — Сканер-ВС
32684
exploitdb · https://www.exploit-db.com/exploits/32684
Enterprise
7585
exploitdb · https://www.exploit-db.com/exploits/7585
Enterprise
Affected products
ProductVendorStatus
windows_media_player*Tracked
Source databases
CVE