Vulnerabilities > CVE-2014-10024 - Numeric Errors vulnerability in Divx Directshowdemuxfilter, Player and web Player

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
divx
CWE-189

Summary

Multiple integer signedness errors in DirectShowDemuxFilter, as used in Divx Web Player, Divx Player, and other Divx plugins, allow remote attackers to execute arbitrary code via a (1) negative or (2) large value in a Stream Format (STRF) chunk in an AVI file, which triggers a heap-based buffer overflow.

Vulnerable Configurations

Part Description Count
Application
Divx
3

Common Weakness Enumeration (CWE)