CVE-2008-1973

SubEdit Player <4066 - Buffer Overflow

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-1973. PoCs published by grzdyl.

AI-analyzed exploit summary This exploit demonstrates a buffer overflow vulnerability in SubEdit Player build 4066, allowing control over EAX and EDX registers to overwrite a pointer in the PEB structure of ntdll, leading to an access violation. The PoC creates a malformed subtitle file to trigger the overflow.

Description

Heap-based buffer overflow in SubEdit Player build 4056 and 4066 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long subtitle file.

Exploits (1)

exploitdb WORKING POC VERIFIED
by grzdyl · pythondoswindows
https://www.exploit-db.com/exploits/5472

This exploit demonstrates a buffer overflow vulnerability in SubEdit Player build 4066, allowing control over EAX and EDX registers to overwrite a pointer in the PEB structure of ntdll, leading to an access violation. The PoC creates a malformed subtitle file to trigger the overflow.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: SubEdit Player build 4066
No auth needed
Prerequisites: SubEdit Player build 4066 installed on Windows XP SP2 · Ability to deliver the malformed subtitle file to the target
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/29904
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/1306
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/41913
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/5472
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/28858

Scores

EPSS 0.0576
EPSS Percentile 92.2%

Details

CWE
CWE-119
Status published
Products (2)
artur_sikora/subedit_player 4056
artur_sikora/subedit_player 4066
Published Apr 27, 2008
Tracked Since Feb 18, 2026