CVE-2009-20003 describes a stack-based buffer overflow in Xenorate multimedia player versions up to 2.50. This vulnerability, categorized as CWE-121, allows an attacker to achieve arbitrary code execution by crafting a malicious .xpl playlist file that overwrites the Structured Exception Handler (SEH). With a CVSS score of 8.4 (HIGH), exploitation requires user interaction to open the malicious file, but the impact on confidentiality, integrity, and availability is high. While not actively exploited in the wild (KEV: No), a Metasploit module exists, indicating readily available exploit code. Despite this, community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Xenorate | Xenorate | >= 0, <= 2.50CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.