peter bassill · operator
$ cve CVE-2009-0476 JSON

CVE-2009-0476 EXPLOIT

9.3
HIGH · CVSS 2.0 · EPSS 37% (pctl 98)

Patch early

A public exploit exists.

Description

Stack-based buffer overflow in MultiMedia Soft AdjMmsEng.dll 7.11.1.0 and 7.11.2.7, as distributed in multiple MultiMedia Soft audio components for .NET, allows remote attackers to execute arbitrary code via a long string in a playlist (.pls) file, as originally reported for Euphonics Audio Player 1.0. NOTE: some of these details are obtained from third party information.

Scoring

CVSS9.3 (HIGH, v2.0)
VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS37.04% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploityes
Published2009-02-08
Last modified2026-06-16

Affected (5)

VendorProduct
multimediasoftaudio dj studio for .net
multimediasoftaudio sound editer for .net
multimediasoftaudio sound recorder for .net
multimediasoftaudio sound studio for .net
multimediasoftaudio sound suite for .net

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD