Loading...
Loading...
Format string vulnerability in the ws_addarg function in webserver.c in mt-dappd in Firefly Media Server 0.2.4 and earlier allows remote attackers to execute arbitrary code via a stats method action to /xml-rpc with format string specifiers in the (1) username or (2) password portion of base64-encoded data on the "Authorization: Basic" HTTP header line.
November 5, 2007
April 23, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2007-5825
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.