8.8
CVSSv3

CVE-2009-0182

CVSSv4: NA | CVSSv3: 8.8 | CVSSv2: 9.3 | VMScore: 980 | EPSS: 0.03414 | KEV: Not Included
Published: 20/01/2009 Updated: 21/11/2024

Vulnerability Summary

Buffer overflow in VUPlayer 2.49 and previous versions allows user-assisted malicious users to execute arbitrary code via a long URL in a File line in a .pls file, as demonstrated by an http URL on a File1 line.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

vuplayer vuplayer

Exploits

#!/usr/bin/perl # VUPlayer <= 249 PLS Universal Buffer Overflow Exploit # ------------------------------------------------------- # Discovered & Exploit by SkD (skdrat _at_ hotmailcom) & # (skd _at_ abyssseccom) # ------------------------------------------------------- # This is a pretty cool player considering it is # freewa ...
VUPlayer version 249 wax local buffer overflow exploit with DEP bypass ...

Github Repositories

CVE-2009-0182 VUPlayer2.49_LocalBufferOverflow

VUPlayer 249 Local Buffer Overflow to Arbitrary Code Execution Program Version: VUPlayer 249 Vulnerability: local buffer overflow when importing wax playlist file that will lead to arbitrary code execution Exploitation: Local Buffer Overflow CVE: CVE-2009-0182 VUPlayer249_pocpy : without bypass DEP protection VUPlayer249_poc_bypassDEPpy : bypass DEP protecti

CVE-2009-0182 VUPlayer2.49_LocalBufferOverflow

VUPlayer 249 Local Buffer Overflow to Arbitrary Code Execution Program Version: VUPlayer 249 Vulnerability: local buffer overflow when importing wax playlist file that will lead to arbitrary code execution Exploitation: Local Buffer Overflow CVE: CVE-2009-0182 VUPlayer249_pocpy : without bypass DEP protection VUPlayer249_poc_bypassDEPpy : bypass DEP protecti

CVE-2009-0182 VUPlayer2.49_LocalBufferOverflow

VUPlayer 249 Local Buffer Overflow to Arbitrary Code Execution Program Version: VUPlayer 249 Vulnerability: local buffer overflow when importing wax playlist file that will lead to arbitrary code execution Exploitation: Local Buffer Overflow CVE: CVE-2009-0182 VUPlayer249_pocpy : without bypass DEP protection VUPlayer249_poc_bypassDEPpy : bypass DEP protecti