CVE-2006-4131

Arcsoft Mms Composer < 1.5.5.6 - Buffer Overflow

Title source: rule

Description

Multiple buffer overflows in ArcSoft MMS Composer 1.5.5.6, and possibly earlier, and 2.0.0.13, and possibly earlier, allow remote attackers to cause a denial of service (crash) or execute arbitrary code via crafted MMS (Multimedia Messaging Service) messages that trigger the overflows in the (1) M-Notification.ind, (2) M-Retrieve.conf (Header and Body), or (3) SMIL parsers.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Collin Mulliner · cdoshardware
https://www.exploit-db.com/exploits/2156
exploitdb WRITEUP VERIFIED
by Collin R. Mulliner · textremotemultiple
https://www.exploit-db.com/exploits/28368

Scores

EPSS 0.2994
EPSS Percentile 96.7%

Details

Status published
Products (1)
arcsoft/mms_composer < 1.5.5.6
Published Aug 14, 2006
Tracked Since Feb 18, 2026