CVE-2009-1627 identifies a critical stack-based buffer overflow vulnerability in Streaming Download Project (SDP) Downloader 2.3.0. This flaw allows remote attackers to achieve arbitrary code execution by providing a specially crafted .asx file with an overly long .asf URL in the HREF attribute. With a CVSS score of 9.3, it poses a high-severity risk, enabling complete compromise of confidentiality, integrity, and availability with medium attack complexity over the network. Although not in CISA's KEV, this vulnerability is on a "Hot List: Active" and has multiple public Proof-of-Concept exploits available, indicating a high potential for exploitation and continued community attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.3.0CPE matchmatch criteria | cpe:2.3:a:sdp_multimedia:streaming_download_project:2.3.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.