CVE-2008-5276
Estado: ModificadaAlta (9.3)—
Integer overflow in the ReadRealIndex function in real.c in the Real demuxer plugin in VideoLAN VLC media player 0.9.0 through 0.9.7 allows remote attackers to execute arbitrary code via a malformed RealMedia (.rm) file that triggers a heap-based buffer overflow.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C
- Puntuación base: 9.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 7.84%
- Percentil entre todas las CVEs puntuadas: 95
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-189
Referencias
- http://git.videolan.org/?p=vlc.git%3Ba=commitdiff%3Bh=d19de4e9f2211cbe5bde00726b66c47a424f4e07
- http://secunia.com/advisories/32942
- http://secunia.com/advisories/33315
- http://security.gentoo.org/glsa/glsa-200812-24.xml
- http://securityreason.com/securityalert/4680
- http://www.osvdb.org/50333
- http://www.securityfocus.com/archive/1/498768/100/0/threaded
- http://www.securityfocus.com/bid/32545
- http://www.trapkit.de/advisories/TKADV2008-013.txt
- http://www.videolan.org/security/sa0811.html
- http://www.vupen.com/english/advisories/2008/3287
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14793
- http://git.videolan.org/?p=vlc.git%3Ba=commitdiff%3Bh=d19de4e9f2211cbe5bde00726b66c47a424f4e07
- http://secunia.com/advisories/32942
- http://secunia.com/advisories/33315
- http://security.gentoo.org/glsa/glsa-200812-24.xml
- http://securityreason.com/securityalert/4680
- http://www.osvdb.org/50333
- http://www.securityfocus.com/archive/1/498768/100/0/threaded
- http://www.securityfocus.com/bid/32545
- http://www.trapkit.de/advisories/TKADV2008-013.txt
- http://www.videolan.org/security/sa0811.html
- http://www.vupen.com/english/advisories/2008/3287
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14793
JSON original (NVD)
Mostrar
{
"id": "CVE-2008-5276",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 9.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": true,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2008-12-03T17:30:00.417",
"references": [
{
"url": "http://git.videolan.org/?p=vlc.git%3Ba=commitdiff%3Bh=d19de4e9f2211cbe5bde00726b66c47a424f4e07",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/32942",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/33315",
"source": "cve@mitre.org"
},
{
"url": "http://security.gentoo.org/glsa/glsa-200812-24.xml",
"source": "cve@mitre.org"
},
{
"url": "http://securityreason.com/securityalert/4680",
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/50333",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/498768/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/32545",
"source": "cve@mitre.org"
},
{
"url": "http://www.trapkit.de/advisories/TKADV2008-013.txt",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.videolan.org/security/sa0811.html",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2008/3287",
"source": "cve@mitre.org"
},
{
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14793",
"source": "cve@mitre.org"
},
{
"url": "http://git.videolan.org/?p=vlc.git%3Ba=commitdiff%3Bh=d19de4e9f2211cbe5bde00726b66c47a424f4e07",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/32942",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/33315",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://security.gentoo.org/glsa/glsa-200812-24.xml",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://securityreason.com/securityalert/4680",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/50333",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/498768/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/32545",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.trapkit.de/advisories/TKADV2008-013.txt",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.videolan.org/security/sa0811.html",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2008/3287",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14793",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-189"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Integer overflow in the ReadRealIndex function in real.c in the Real demuxer plugin in VideoLAN VLC media player 0.9.0 through 0.9.7 allows remote attackers to execute arbitrary code via a malformed RealMedia (.rm) file that triggers a heap-based buffer overflow."
},
{
"lang": "es",
"value": "Desbordamiento de entero en la función ReadRealIndex en el archivo real.c en el Real demuxer plugin en reproductor multimedia VideoLAN VLC desde la versión 0.9.0 hasta 0.9.7, permite a los atacante remotos ejecutar arbitrariamente código a través de ficheros RealMedia (.rm) mal formados que lanzan un desbordamiento de búfer basado en montículo."
}
],
"lastModified": "2026-06-16T22:59:37.053",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:videolan:vlc_media_player:0.9.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C13FF305-2547-4E85-9007-0A89F5E34BD4"
},
{
"criteria": "cpe:2.3:a:videolan:vlc_media_player:0.9.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3E93836E-E9D1-4180-A589-43602647741C"
},
{
"criteria": "cpe:2.3:a:videolan:vlc_media_player:0.9.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B3B32073-DBD5-4344-8498-A132B99807A8"
},
{
"criteria": "cpe:2.3:a:videolan:vlc_media_player:0.9.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5330E5C4-BF18-498A-9AE2-1C57E2494AAF"
},
{
"criteria": "cpe:2.3:a:videolan:vlc_media_player:0.9.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "86D31A16-94EE-45D6-8C54-4F27D466A29E"
},
{
"criteria": "cpe:2.3:a:videolan:vlc_media_player:0.9.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "117C896C-1C61-440E-B0F4-A871828CD095"
},
{
"criteria": "cpe:2.3:a:videolan:vlc_media_player:0.9.6:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "53C17E1A-2E3A-4765-92DE-55CFEE5E4CB0"
},
{
"criteria": "cpe:2.3:a:videolan:vlc_media_player:0.9.7:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "117878B7-E04F-400E-8E63-FFC5420978A8"
},
{
"criteria": "cpe:2.3:a:videolan:vlc_media_player:0.9.8:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8815D85E-1556-40A8-9465-0200D720444B"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}