CVE-2007-1559
Multiple stack-based buffer overflows in SonicDVDDashVRNav.dll in Roxio CinePlayer 3.2 allow remote attackers to execute arbitrary code via (1) unspecified long property values to SonicMediaPlayer.dll or (2) long arguments to unspecified methods in…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 31.8%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
Multiple stack-based buffer overflows in SonicDVDDashVRNav.dll in Roxio CinePlayer 3.2 allow remote attackers to execute arbitrary code via (1) unspecified long property values to SonicMediaPlayer.dll or (2) long arguments to unspecified methods in SonicMediaPlayer.dll.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 31.81% probability · 98th percentile
- CISA KEV
- Not listed
- Affected
- roxio/cineplayer
- Source
- PSIRT-CNA@flexerasoftware.com
References
- http://osvdb.org/34779
- http://secunia.com/advisories/22251Vendor Advisory
- http://secunia.com/secunia_research/2007-46/advisory/Vendor Advisory
- http://www.securityfocus.com/bid/23412
- http://www.securitytracker.com/id?1017906
- http://www.vupen.com/english/advisories/2007/1337
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33590
- http://osvdb.org/34779
- http://secunia.com/advisories/22251Vendor Advisory
- http://secunia.com/secunia_research/2007-46/advisory/Vendor Advisory
- http://www.securityfocus.com/bid/23412
- http://www.securitytracker.com/id?1017906
- http://www.vupen.com/english/advisories/2007/1337
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33590
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.