CVE-2018-0429 describes a stack-based buffer overflow vulnerability in the Cisco Thor video codec, specifically affecting versions prior to commit 18de8f9f0762c3a542b1122589edb8af859d9813. This flaw, rated 7.8 HIGH, allows a local attacker to trigger a denial of service or execute arbitrary code by providing a specially crafted, non-conformant Thor bitstream. While the potential impact is significant, there is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2018-8-8CPE matchmatch criteria | cpe:2.3:a:cisco:thor_video_codec:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.