9.3
CVSSv2

CVE-2009-1370

Published: 22/04/2009 Updated: 29/09/2017
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Stack-based buffer overflow in ape_plugin.plg in Xilisoft Video Converter 3.1.53.0704n and 5.1.23.0402 allows remote malicious users to cause a denial of service (crash) and possibly execute arbitrary code via a long string in a .cue file.

Vulnerable Product Search on Vulmon Subscribe to Product

xilisoft xilisoft video converter 3.1.53

xilisoft xilisoft video converter 5.1.23

Exploits

/* ---------------------------------------------------------------------------------------- Xilisoft Video Converter Wizard 3 CUE File Stack Buffer Overflow POC name: xilisoftcpp Credits : fl0 fl0w ---------------------------------------------------------------------------------------- ScreanShot in the debugger Link: wwwdownloadatozc ...