Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9q4v-vqp5-xxh4

Опубликовано: 20 авг. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.5

Описание

Subtitle Processor 7.7.1 contains a buffer overflow vulnerability in its .m3u file parser. When a crafted playlist file is opened, the application converts input to Unicode and copies it to a fixed-size stack buffer without proper bounds checking. This allows an attacker to overwrite the Structured Exception Handler (SEH) and execute arbitrary code.

Subtitle Processor 7.7.1 contains a buffer overflow vulnerability in its .m3u file parser. When a crafted playlist file is opened, the application converts input to Unicode and copies it to a fixed-size stack buffer without proper bounds checking. This allows an attacker to overwrite the Structured Exception Handler (SEH) and execute arbitrary code.

EPSS

Процентиль: 92%
0.08151
Низкий

8.5 High

CVSS4

Дефекты

CWE-120

Связанные уязвимости

nvd
6 месяцев назад

Subtitle Processor 7.7.1 contains a buffer overflow vulnerability in its .m3u file parser. When a crafted playlist file is opened, the application converts input to Unicode and copies it to a fixed-size stack buffer without proper bounds checking. This allows an attacker to overwrite the Structured Exception Handler (SEH) and execute arbitrary code.

EPSS

Процентиль: 92%
0.08151
Низкий

8.5 High

CVSS4

Дефекты

CWE-120