Vulnerability Details CVE-2014-10024
Multiple integer signedness errors in DirectShowDemuxFilter, as used in Divx Web Player, Divx Player, and other Divx plugins, allow remote attackers to execute arbitrary code via a (1) negative or (2) large value in a Stream Format (STRF) chunk in an AVI file, which triggers a heap-based buffer overflow.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.034
EPSS Ranking 86.7%
CVSS Severity
CVSS v2 Score 7.5
Products affected by CVE-2014-10024
-
cpe:2.3:a:divx:directshowdemuxfilter:-
-
cpe:2.3:a:divx:player:6.0
-
cpe:2.3:a:divx:player:6.1
-
cpe:2.3:a:divx:player:6.1.1
-
cpe:2.3:a:divx:player:6.2
-
cpe:2.3:a:divx:player:6.3
-
cpe:2.3:a:divx:player:6.3.2
-
cpe:2.3:a:divx:player:6.4
-
cpe:2.3:a:divx:player:6.4.1
-
cpe:2.3:a:divx:player:6.4.2
-
cpe:2.3:a:divx:player:6.4.3
-
cpe:2.3:a:divx:player:6.5
-
cpe:2.3:a:divx:player:6.6
-
cpe:2.3:a:divx:player:6.7
-
cpe:2.3:a:divx:player:6.8
-
cpe:2.3:a:divx:player:6.8.2
-
cpe:2.3:a:divx:player:7.0
-
cpe:2.3:a:divx:player:7.1
-
cpe:2.3:a:divx:player:7.2
-
cpe:2.3:a:divx:web_player:1.0.0
-
cpe:2.3:a:divx:web_player:1.1.0
-
cpe:2.3:a:divx:web_player:1.2.0
-
cpe:2.3:a:divx:web_player:1.3.0
-
cpe:2.3:a:divx:web_player:1.5.0