CVE-2009-0182

HIGH

VUPlayer <2.49 - RCE

Title source: llm

Description

Buffer overflow in VUPlayer 2.49 and earlier allows user-assisted attackers to execute arbitrary code via a long URL in a File line in a .pls file, as demonstrated by an http URL on a File1 line.

Exploits (4)

exploitdb WORKING POC VERIFIED
by SkD · perllocalwindows
https://www.exploit-db.com/exploits/7695
exploitdb WORKING POC
by Bryan Leong · pythonlocalwindows
https://www.exploit-db.com/exploits/50650
nomisec WORKING POC
by nobodyatall648 · poc
https://github.com/nobodyatall648/CVE-2009-0182
metasploit WORKING POC GOOD
by MC · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/fileformat/vuplayer_cue.rb

Scores

CVSS v3 8.8
EPSS 0.7902
EPSS Percentile 99.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-120
Status published
Products (1)
vuplayer/vuplayer < 2.49
Published Jan 20, 2009
Tracked Since Feb 18, 2026