CVE-2012-10031 describes a stack-based buffer overflow in BlazeVideo HDTV Player Pro v6.6.0.3. This vulnerability occurs when the MediaPlayerCtrl.dll component improperly handles crafted .plf playlist files, specifically due to an unbounded strcpy operation during filename extraction. A successful exploit allows for arbitrary code execution under the context of the user. The vulnerability carries a high CVSS score of 8.6, indicating a critical risk. It can be exploited remotely with low attack complexity, requiring user interaction to open a malicious .plf file, and has a high impact on confidentiality, integrity, and availability. While not listed on CISA's KEV catalog, exploit intelligence shows a Metasploit module exists, confirming exploitability. Community discussion is notably high, with 20 mentions, suggesting significant interest among security researchers despite no reported active exploitation or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| BlazeVideo Inc. | HDTV Player Pro | 6.6.0.3CNA affecteddefault unknown |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.