← Back

CVE-2008-2147

nvd nist
Published: May 12, 2008Modified: Apr 23, 2026

JSON object

Loading...
4.6
Vector
AV:L/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 3.9 / Impact: 6.4
Source: NVD

Description

Untrusted search path vulnerability in VideoLAN VLC before 0.9.0 allows local users to execute arbitrary code via a malicious library under the modules/ or plugins/ subdirectories of the current working directory.

Affected (24)

Products: Videolan: Vlc
1 product
Vlc
Configuration A
24 vulnerable
Vulnerable SoftwareAffected Versions
Videolan
Up to 0.8.6
Version 0.4.6
Version 0.5.0
Version 0.5.1
Version 0.5.1a
Version 0.5.2
Version 0.5.3
Version 0.6.0
Version 0.6.1
Version 0.6.2
Version 0.7.0
Version 0.7.1
Version 0.7.2
Version 0.8.0
Version 0.8.1
Version 0.8.2
Version 0.8.4
Version 0.8.4a
Version 0.8.5
Version 0.8.6a
Version 0.8.6b
Version 0.8.6c
Version 0.8.6d
Version 0.8.6e

Related CWEs

Timeline

No history available yet.