9.3
CVSSv2

CVE-2009-1356

Published: 21/04/2009 Updated: 29/09/2017
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Stack-based buffer overflow in Elecard AVC HD Player allows remote malicious users to execute arbitrary code via a long MP3 filename in a playlist (.xpl) file.

Vulnerable Product Search on Vulmon Subscribe to Product

elecard elecard avc hd player

Exploits

/*ELECARD AVC HD PLAYER STACK BUFFER OVERFLOW ( SEH OVERWRITE ) Name: elecardc CREDITS: the one and only fl0 fl0w 004533AE F3:A5 REP MOVS DWORD PTR ES:[EDI],DWORD PTR DS> SEH chain of main thread Address SE handler 0012CB54 FFFFFFFF Open in debugger and you'll see SEH -->FFFFFFFF and NEXT_SEH EB049090 */ //START #includ ...