9.3
CVSSv2

CVE-2009-4840

Published: 06/05/2010 Updated: 19/09/2017
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Heap-based buffer overflow in the IAManager ActiveX control in IAManager.dll in Roxio CinePlayer 3.2 allows remote malicious users to execute arbitrary code via a long argument to the SetIAPlayerName method.

Vulnerable Product Search on Vulmon Subscribe to Product

roxio cineplayer 3.2

Exploits

<html> <head> <title>Boom!</title> <br>Roxio CinePlayer 32 (IAManagerdll) Remote BOF Exploit (heap spray)</br> <br>Advisory from secunia 22251</br> <br>By : His0k4</br> <br>Greetings: All friends (dz), snakespccom</br> <br>Tested on Windows Xp Sp3 (en),with IE7</ ...