A stack-based buffer overflow exists in the parse_master function of the Ty demux plugin (modules/demux/ty.c) in VLC Media Player versions 0.9.0 through 0.9.4. The vulnerability is triggered when a specially crafted TiVo TY media file with a malicious header containing a crafted size value is processed, leading to a buffer overflow on the stack.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository contains a single Metasploit module (modules/exploits/windows/fileformat/videolan_tivo.rb) that exploits a buffer overflow vulnerability (CVE-2008-4654) in VideoLAN VLC versions 0.9.2 and 0.9.4 on Windows XP SP3 English. The exploit works by generating a specially crafted .ty (TiVo) file ('msf.ty' by default) that, when opened by a vulnerable VLC instance, triggers a buffer overflow and allows arbitrary code execution. The module allows the attacker to specify a payload, which is embedded in the malicious file. The attack vector is local and user-assisted, requiring the victim to open the malicious file. The code is written in Ruby and is structured as a standard Metasploit exploit module, leveraging the FILEFORMAT mixin to handle file creation. No network endpoints or remote services are targeted; the only fingerprintable endpoint is the generated file itself.
This repository contains a Python script (CVE-2008-4654.py) and a README.md. The script is an exploit for CVE-2008-4654, a stack-based buffer overflow in VLC Media Player 0.9.4 when processing TiVo files. The exploit works by modifying a legitimate TiVo file: it searches for a specific file ID pattern, overwrites a field to trigger the overflow, and injects a payload consisting of a JMP ESP address, a WOW64 egghunter, and user-supplied shellcode. The egghunter locates the shellcode in memory and executes it, bypassing stack size limitations on 64-bit Windows systems. The README provides detailed usage instructions, including how to generate shellcode (e.g., with msfvenom), and describes the exploit's operation and requirements. The exploit is operational but requires the user to supply their own shellcode. The main attack vector is local: the victim must open the weaponized TiVo file in VLC. No network endpoints or remote services are targeted directly. The repository is well-structured, with clear documentation and a single Python exploit script.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.