CVE-2006-4046

Open Cubic Player < 0.1.10_rc5 - Remote Code Execution via Crafted .S3M, .IT, .ULT, or .AMS File

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2006-4046. PoCs published by Luigi Auriemma.

AI-analyzed exploit summary This exploit generates malformed S3M, IT, ULT, or AMS files to trigger buffer overflows in Open Cubic Player. It demonstrates multiple vulnerabilities by crafting files with excessive data lengths.

Description

Multiple stack-based buffer overflows in Open Cubic Player 2.6.0pre6 and earlier for Windows, and 0.1.10_rc5 and earlier on Linux/BSD, allow remote attackers to execute arbitrary code via (1) a large .S3M file handled by the mpLoadS3M function, (2) a crafted .IT file handled by the itplayerclass::module::load function, (3) a crafted .ULT file handled by the mpLoadULT function, or (4) a crafted .AMS file handled by the mpLoadAMS function.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Luigi Auriemma · clocalwindows
https://www.exploit-db.com/exploits/2094

This exploit generates malformed S3M, IT, ULT, or AMS files to trigger buffer overflows in Open Cubic Player. It demonstrates multiple vulnerabilities by crafting files with excessive data lengths.

Classification
Working Poc 100%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: Open Cubic Player <= 2.6.0pre6 / 0.1.10_rc5
No auth needed
Prerequisites: None
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (12)

Core 12
Core References
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/21267
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/28104
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/1349
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/19262
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/2094
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/441730/100/100/threaded
Third Party Advisory x_refsource_misc
http://aluigi.altervista.org/adv/ocpbof-adv.txt
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/3078
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/28103
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/28106
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1016611
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/28105

Scores

EPSS 0.1449
EPSS Percentile 96.2%

Details

Status published
Products (1)
open_cubic_player/open_cubic_player < 0.1.10_rc5
Published Aug 09, 2006
Tracked Since Feb 18, 2026