vendor:
Xion Audio Player
by:
Dragon Rider
9.3
CVSS
HIGH
Local and Remote Code Execution
119
CWE
Product Name: Xion Audio Player
Affected Version From: 1.0 build 121
Affected Version To: 1.0 build 121
Patch Exists: YES
Related CWE: N/A
CPE: a:xion_audio_player:xion_audio_player
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2009
Xion Audio Player Local BOF
Xion Audio Player is prone to a buffer-overflow vulnerability because it fails to properly bounds-check user-supplied data before copying it into an insufficiently sized memory buffer. An attacker can exploit this issue to execute arbitrary code in the context of the application. Failed exploit attempts will result in a denial-of-service condition.
Mitigation:
Upgrade to the latest version of Xion Audio Player