CVE-2008-0619

Nero MediaPlayer < 1.4.0.35 - Remote Code Execution via Long URI in M3U File

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-0619. PoCs published by securfrog.

AI-analyzed exploit summary This exploit triggers a remote buffer overflow in Nero Media Player by creating a malicious .M3U file with an overly long HTTP URL. The crash occurs when the player processes the file, leading to an access violation.

Description

Buffer overflow in NeroMediaPlayer.exe in Nero Media Player 1.4.0.35 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (persistent crash) via a long URI in a .M3U file.

Exploits (1)

exploitdb WORKING POC VERIFIED
by securfrog · perldoswindows
https://www.exploit-db.com/exploits/5063

This exploit triggers a remote buffer overflow in Nero Media Player by creating a malicious .M3U file with an overly long HTTP URL. The crash occurs when the player processes the file, leading to an access violation.

Classification
Working Poc 90%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: Nero Media Player <= 1.4.0.35b
No auth needed
Prerequisites: Ability to deliver a malicious .M3U file to the target
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/28765
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/27615
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/3616
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/5063
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/487578/100/0/threaded
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/0405

Scores

EPSS 0.1076
EPSS Percentile 95.3%

Details

CWE
CWE-119
Status published
Products (1)
nero/mediaplayer < 1.4.0.35
Published Feb 06, 2008
Tracked Since Feb 18, 2026