CVE-2011-0042

SBE.dll in the Stream Buffer Engine in Windows Media Player and Windows Media Center in Microsoft Windows XP SP2 and SP3, Windows XP Media Center Edition 2005 SP3, Windows Vista SP1 and SP2, Windows 7 Gold and SP1, and Windows Media Center TV Pack for Windows Vista does not properly parse Digital Video Recording (.dvr-ms) files, which allows remote attackers to execute arbitrary code via a crafted file, aka "DVR-MS Vulnerability."
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:microsoft:windows_xp_media_center:2005:sp3:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_7:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_7:-:sp1:x64:*:*:*:*:*
cpe:2.3:o:microsoft:windows_7:-:sp1:x86:*:*:*:*:*
cpe:2.3:o:microsoft:windows_vista:*:sp1:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_vista:*:sp2:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_xp:*:sp2:x64:*:*:*:*:*
cpe:2.3:o:microsoft:windows_xp:*:sp3:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:a:microsoft:windows_media_center_tv_pack:*:*:*:*:*:*:*:*
OR cpe:2.3:o:microsoft:windows_vista:*:*:x32:*:*:*:*:*
cpe:2.3:o:microsoft:windows_vista:*:*:x64:*:*:*:*:*

History

21 Jan 2025, 18:15

Type Values Removed Values Added
CVSS v2 : 9.3
v3 : unknown
v2 : 9.3
v3 : 7.8

21 Nov 2024, 01:23

Type Values Removed Values Added
References () http://osvdb.org/71016 - () http://osvdb.org/71016 -
References () http://secunia.com/advisories/43626 - () http://secunia.com/advisories/43626 -
References () http://www.securityfocus.com/bid/46680 - () http://www.securityfocus.com/bid/46680 -
References () http://www.securitytracker.com/id?1025169 - () http://www.securitytracker.com/id?1025169 -
References () http://www.us-cert.gov/cas/techalerts/TA11-067A.html - US Government Resource () http://www.us-cert.gov/cas/techalerts/TA11-067A.html - US Government Resource
References () http://www.vupen.com/english/advisories/2011/0615 - () http://www.vupen.com/english/advisories/2011/0615 -
References () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-015 - () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-015 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12281 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12281 -

07 Dec 2023, 18:38

Type Values Removed Values Added
CPE cpe:2.3:o:microsoft:windows_vista:*:sp1:x64:*:*:*:*:*
cpe:2.3:o:microsoft:windows_vista:*:sp2:x64:*:*:*:*:*

Information

Published : 2011-03-09 23:00

Updated : 2025-01-21 18:15


NVD link : CVE-2011-0042

Mitre link : CVE-2011-0042

CVE.ORG link : CVE-2011-0042


JSON object : View

Products Affected

microsoft

  • windows_media_center_tv_pack
  • windows_xp_media_center
  • windows_vista
  • windows_xp
  • windows_7
CWE
CWE-20

Improper Input Validation