CVE-2009-1437
high · 9.3Stack-based buffer overflow in PortableApps CoolPlayer Portable (aka CoolPlayer+ Portable) 2.19.6 and earlier allows remote attackers to execute arbitrary code via a long string in a malformed playlist (.m3u) file. NOTE: this may overlap CVE-2008-3408.
9.3
CVSS
14.0%
EPSS (exploit prob.)
96th
EPSS percentile
2009-04-27
Published
AV:N/AC:M/Au:N/C:C/I:C/A:C
Weaknesses
CWE-119
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| coolplayer | coolplayer | 2.19.1 |
Check a specific version with /api/v1/cve/match.
References
- http://osvdb.org/53885
- http://secunia.com/advisories/34816
- https://exchange.xforce.ibmcloud.com/vulnerabilities/49984
- https://hansesecure.de/vulnerability-in-coolplayer/
- https://www.exploit-db.com/exploits/8489
- https://www.exploit-db.com/exploits/8519
- https://www.exploit-db.com/exploits/8520
- http://osvdb.org/53885
- http://secunia.com/advisories/34816
- https://exchange.xforce.ibmcloud.com/vulnerabilities/49984
- https://hansesecure.de/vulnerability-in-coolplayer/
- https://www.exploit-db.com/exploits/8489
- https://www.exploit-db.com/exploits/8519
- https://www.exploit-db.com/exploits/8520
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2009-1437