CVE-2009-1327 describes a stack-based buffer overflow in Mini-stream WM Downloader 3.0.0.9, allowing remote attackers to execute arbitrary code through a crafted playlist (.m3u) file containing an overly long URI. This vulnerability carries a critical CVSS score of 9.3, indicating a high severity due to its network-based attack vector, low authentication requirements, and complete compromise of confidentiality, integrity, and availability. While not actively exploited in the wild (no KEV entry), proof-of-concept exploit code is publicly available on ExploitDB for several related Mini-stream products, suggesting a clear path for exploitation. Despite the availability of PoCs, there is minimal community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.0.0.9CPE matchmatch criteria | cpe:2.3:a:mini-stream:wm_downloader:3.0.0.9:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.