CVE-2008-4686
Last modified
CVE-2008-4686 is a vulnerability of currently unknown severity. Multiple integer overflows in ty.c in the TY demux plugin (aka the TiVo demuxer) in VideoLAN VLC media player, probably 0.9.4, might allow remote attackers to execute arbitrary code via a crafted .ty file, a different vulnerability than CVE-2008-4654.. EPSS estimates a 9.94% chance of exploitation in the next 30 days.
Description
Multiple integer overflows in ty.c in the TY demux plugin (aka the TiVo demuxer) in VideoLAN VLC media player, probably 0.9.4, might allow remote attackers to execute arbitrary code via a crafted .ty file, a different vulnerability than CVE-2008-4654.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Videolan | Vlc Media Player | 0.9.0 |
| Videolan | Vlc Media Player | 0.9.1 |
| Videolan | Vlc Media Player | 0.9.2 |
| Videolan | Vlc Media Player | 0.9.3 |
| Videolan | Vlc Media Player | 0.9.4 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-4686?
How severe is CVE-2008-4686?
How do I fix CVE-2008-4686?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2008
- CVE-2008-4680packet-usb.c in the USB dissector in Wireshark 0.99.7 throug…
- CVE-2008-4681Unspecified vulnerability in the Bluetooth RFCOMM dissector …
- CVE-2008-4682wtap.c in Wireshark 0.99.7 through 1.0.3 allows remote attac…
- CVE-2008-4683The dissect_btacl function in packet-bthci_acl.c in the Blue…
- CVE-2008-4684packet-frame in Wireshark 0.99.2 through 1.0.3 does not prop…
- CVE-2008-4685Use-after-free vulnerability in the dissect_q931_cause_ie fu…
- CVE-2008-4687manage_proj_page.php in Mantis before 1.1.4 allows remote au…
- CVE-2008-4688core/string_api.php in Mantis before 1.1.3 does not check th…
- CVE-2008-4689Mantis before 1.1.3 does not unset the session cookie during…
- CVE-2008-4690lynx 2.8.6dev.15 and earlier, when advanced mode is enabled …
- CVE-2008-4691Unspecified vulnerability in the SQLNLS_UNPADDEDCHARLEN func…
- CVE-2008-4692The Native Managed Provider for .NET component in IBM DB2 8 …
Are you affected by CVE-2008-4686?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
