8.8
CVSSv3

CVE-2009-0182

Published: 20/01/2009 Updated: 22/04/2022
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 936
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Buffer overflow in VUPlayer 2.49 and previous versions allows user-assisted malicious users to execute arbitrary code via a long URL in a File line in a .pls file, as demonstrated by an http URL on a File1 line.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

vuplayer vuplayer

Exploits

#!/usr/bin/perl # VUPlayer <= 249 PLS Universal Buffer Overflow Exploit # ------------------------------------------------------- # Discovered & Exploit by SkD (skdrat _at_ hotmailcom) & # (skd _at_ abyssseccom) # ------------------------------------------------------- # This is a pretty cool player considering it is # freewa ...
VUPlayer version 249 wax local buffer overflow exploit with DEP bypass ...

Github Repositories

CVE-2009-0182 VUPlayer2.49_LocalBufferOverflow

VUPlayer 249 Local Buffer Overflow to Arbitrary Code Execution Program Version: VUPlayer 249 Vulnerability: local buffer overflow when importing wax playlist file that will lead to arbitrary code execution Exploitation: Local Buffer Overflow CVE: CVE-2009-0182 VUPlayer249_pocpy : without bypass DEP protection VUPlayer249_poc_bypassDEPpy : bypass DEP protecti

CVE-2009-0182 VUPlayer2.49_LocalBufferOverflow

VUPlayer 249 Local Buffer Overflow to Arbitrary Code Execution Program Version: VUPlayer 249 Vulnerability: local buffer overflow when importing wax playlist file that will lead to arbitrary code execution Exploitation: Local Buffer Overflow CVE: CVE-2009-0182 VUPlayer249_pocpy : without bypass DEP protection VUPlayer249_poc_bypassDEPpy : bypass DEP protecti

CVE-2009-0182 VUPlayer2.49_LocalBufferOverflow

VUPlayer 249 Local Buffer Overflow to Arbitrary Code Execution Program Version: VUPlayer 249 Vulnerability: local buffer overflow when importing wax playlist file that will lead to arbitrary code execution Exploitation: Local Buffer Overflow CVE: CVE-2009-0182 VUPlayer249_pocpy : without bypass DEP protection VUPlayer249_poc_bypassDEPpy : bypass DEP protecti