Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2009-1022

36
FAUCET Score

CVE-2009-1022 describes a heap-based buffer overflow in Gretech GOMlab GOM Encoder version 1.0.0.11 and earlier. This vulnerability occurs in the Preview/Set Segment function when processing a specially crafted subtitle (.srt) file containing an excessively long text field. The vulnerability carries a critical CVSS score of 9.3, indicating a high severity. An unauthenticated, remote attacker could exploit this with user assistance (e.g., tricking a user into opening a malicious .srt file), leading to a denial of service through memory corruption and application crashes, or potentially arbitrary code execution. While not listed on the CISA KEV catalog or actively exploited, proof-of-concept exploit code is publicly available on ExploitDB. Despite its age and high severity, there is no significant community discussion or media coverage surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
<= 1.0.0.11CPE matchmatch criteria
cpe:2.3:a:gomlab:gom_encoder:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

9.3HIGH

AV:N/AC:M/Au:N/C:C/I:C/A:C

Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
Access Vector
NETWORK
Access Complexity
MEDIUM
Authentication
NONE
Exploitability Score
8.6
Impact Score
10.0
CvssVersion
2.0

Exploit Intelligence

EPSS Score
7.42%
Probability of exploitation in next 30 days
EPSS Percentile
93.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
ExploitDB: EDB-8225 · Mar 16, 2009
This CVE's current EPSS score of 0.0742 is in the 71st percentile among its peer group of 8,914 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

osvdb.org / 52677
secunia.com / advisories/34314
Vendor Advisory
security.bkis.vn
exchange.xforce.ibmcloud.com / vulnerabilities/49252
exploit-db.com / exploits/8225
securityfocus.com / archive/1/501846/100/0/threaded
securityfocus.com / bid/34120
Exploit
vupen.com / english/advisories/2009/0735
Vendor Advisory