Show plain JSON{"cve": {"data_type": "CVE", "references": {"reference_data": [{"url": "http://www.coresecurity.com/?action=item&id=2103", "name": "http://www.coresecurity.com/?action=item&id=2103", "tags": ["Exploit"], "refsource": "MISC"}, {"url": "http://www.securityfocus.com/bid/27441", "name": "27441", "tags": [], "refsource": "BID"}, {"url": "http://lists.grok.org.uk/pipermail/full-disclosure/2008-February/060033.html", "name": "20080204 CORE-2007-1218: MPlayer 1.0rc2 buffer overflow vulnerability", "tags": [], "refsource": "FULLDISC"}, {"url": "http://www.mplayerhq.hu/design7/news.html", "name": "http://www.mplayerhq.hu/design7/news.html", "tags": [], "refsource": "CONFIRM"}, {"url": "http://secunia.com/advisories/28779", "name": "28779", "tags": ["Vendor Advisory"], "refsource": "SECUNIA"}, {"url": "http://sourceforge.net/project/shownotes.php?group_id=9655&release_id=574735", "name": "http://sourceforge.net/project/shownotes.php?group_id=9655&release_id=574735", "tags": [], "refsource": "CONFIRM"}, {"url": "http://secunia.com/advisories/28801", "name": "28801", "tags": ["Vendor Advisory"], "refsource": "SECUNIA"}, {"url": "http://bugs.xine-project.org/show_bug.cgi?id=38", "name": "http://bugs.xine-project.org/show_bug.cgi?id=38", "tags": [], "refsource": "CONFIRM"}, {"url": "https://bugzilla.redhat.com/show_bug.cgi?id=431541", "name": "https://bugzilla.redhat.com/show_bug.cgi?id=431541", "tags": [], "refsource": "CONFIRM"}, {"url": "http://www.debian.org/security/2008/dsa-1496", "name": "DSA-1496", "tags": [], "refsource": "DEBIAN"}, {"url": "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00395.html", "name": "FEDORA-2008-1543", "tags": [], "refsource": "FEDORA"}, {"url": "https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00442.html", "name": "FEDORA-2008-1581", "tags": [], "refsource": "FEDORA"}, {"url": "http://secunia.com/advisories/28918", "name": "28918", "tags": ["Vendor Advisory"], "refsource": "SECUNIA"}, {"url": "http://secunia.com/advisories/28956", "name": "28956", "tags": ["Vendor Advisory"], "refsource": "SECUNIA"}, {"url": "http://www.mandriva.com/security/advisories?name=MDVSA-2008:045", "name": "MDVSA-2008:045", "tags": [], "refsource": "MANDRIVA"}, {"url": "http://www.mandriva.com/security/advisories?name=MDVSA-2008:046", "name": "MDVSA-2008:046", "tags": [], "refsource": "MANDRIVA"}, {"url": "http://secunia.com/advisories/28955", "name": "28955", "tags": ["Vendor Advisory"], "refsource": "SECUNIA"}, {"url": "http://secunia.com/advisories/28989", "name": "28989", "tags": ["Vendor Advisory"], "refsource": "SECUNIA"}, {"url": "http://bugs.gentoo.org/show_bug.cgi?id=209106", "name": "http://bugs.gentoo.org/show_bug.cgi?id=209106", "tags": [], "refsource": "CONFIRM"}, {"url": "http://security.gentoo.org/glsa/glsa-200802-12.xml", "name": "GLSA-200802-12", "tags": [], "refsource": "GENTOO"}, {"url": "http://secunia.com/advisories/29141", "name": "29141", "tags": ["Vendor Advisory"], "refsource": "SECUNIA"}, {"url": "http://security.gentoo.org/glsa/glsa-200803-16.xml", "name": "GLSA-200803-16", "tags": [], "refsource": "GENTOO"}, {"url": "http://secunia.com/advisories/29307", "name": "29307", "tags": ["Vendor Advisory"], "refsource": "SECUNIA"}, {"url": "http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00004.html", "name": "SUSE-SR:2008:006", "tags": [], "refsource": "SUSE"}, {"url": "http://secunia.com/advisories/29323", "name": "29323", "tags": ["Vendor Advisory"], "refsource": "SECUNIA"}, {"url": "http://www.debian.org/security/2008/dsa-1536", "name": "DSA-1536", "tags": [], "refsource": "DEBIAN"}, {"url": "http://secunia.com/advisories/29601", "name": "29601", "tags": ["Vendor Advisory"], "refsource": "SECUNIA"}, {"url": "http://securityreason.com/securityalert/3608", "name": "3608", "tags": [], "refsource": "SREASON"}, {"url": "http://secunia.com/advisories/31393", "name": "31393", "tags": [], "refsource": "SECUNIA"}, {"url": "http://www.ubuntu.com/usn/usn-635-1", "name": "USN-635-1", "tags": [], "refsource": "UBUNTU"}, {"url": "http://www.vupen.com/english/advisories/2008/0421", "name": "ADV-2008-0421", "tags": [], "refsource": "VUPEN"}, {"url": "http://www.vupen.com/english/advisories/2008/0406/references", "name": "ADV-2008-0406", "tags": [], "refsource": "VUPEN"}, {"url": "http://www.securityfocus.com/archive/1/487501/100/0/threaded", "name": "20080204 CORE-2007-1218: MPlayer 1.0rc2 buffer overflow vulnerability", "tags": [], "refsource": "BUGTRAQ"}]}, "data_format": "MITRE", "description": {"description_data": [{"lang": "en", "value": "Array index vulnerability in libmpdemux/demux_audio.c in MPlayer 1.0rc2 and SVN before r25917, and possibly earlier versions, as used in Xine-lib 1.1.10, might allow remote attackers to execute arbitrary code via a crafted FLAC tag, which triggers a buffer overflow."}]}, "problemtype": {"problemtype_data": [{"description": [{"lang": "en", "value": "CWE-189"}]}]}, "data_version": "4.0", "CVE_data_meta": {"ID": "CVE-2008-0486", "ASSIGNER": "cve@mitre.org"}}, "impact": {"baseMetricV2": {"cvssV2": {"version": "2.0", "baseScore": 7.5, "accessVector": "NETWORK", "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P", "authentication": "NONE", "integrityImpact": "PARTIAL", "accessComplexity": "LOW", "availabilityImpact": "PARTIAL", "confidentialityImpact": "PARTIAL"}, "severity": "HIGH", "impactScore": 6.4, "obtainAllPrivilege": false, "exploitabilityScore": 10.0, "obtainUserPrivilege": false, "obtainOtherPrivilege": true, "userInteractionRequired": false}}, "publishedDate": "2008-02-05T12:00Z", "configurations": {"nodes": [{"children": [], "operator": "OR", "cpe_match": [{"cpe23Uri": "cpe:2.3:a:mplayer:mplayer:1.02rc2:*:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true}, {"cpe23Uri": "cpe:2.3:a:xine:xine-lib:1.1.10:*:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true}]}], "CVE_data_version": "4.0"}, "lastModifiedDate": "2018-10-15T22:00Z"}