CVE-2009-1356 describes a stack-based buffer overflow vulnerability in Elecard AVC HD Player, allowing remote attackers to execute arbitrary code through a crafted MP3 filename within a playlist (.xpl) file. This vulnerability carries a critical CVSS score of 9.3, indicating a high potential for complete compromise of confidentiality, integrity, and availability with medium attack complexity and no authentication required. While not listed on the KEV catalog or showing active exploitation, a proof-of-concept exploit is available on ExploitDB, though there is no evidence of broader community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:elecard:elecard_avc_hd_player:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.