peter bassill · operator
$ cve CVE-2007-6609 JSON

CVE-2007-6609 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 5.2% (pctl 92)

Patch early

A public exploit exists.

Description

Multiple stack-based buffer overflows in the CPLI_ReadTag_OGG function in CPI_PlaylistItem.c in CoolPlayer 217 and earlier allow user-assisted remote attackers to execute arbitrary code via a long (1) cTag or (2) cValue field in an OGG Vorbis file.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
EPSS5.22% — more likely to be exploited than 92% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploityes
Published2007-12-31
Last modified2026-06-16

Affected (1)

VendorProduct
coolplayercoolplayer

Public exploits

SourceTitleDate
exploit-dbCoolPlayer 2.17 - 'CPLI_ReadTag_OGG()' Buffer Overflow2007-12-28

References

→ the Explorer  ·  watch your stack  ·  NVD