CVE-2009-1437

Coolplayer - Memory Corruption

Title source: rule

Description

Stack-based buffer overflow in PortableApps CoolPlayer Portable (aka CoolPlayer+ Portable) 2.19.6 and earlier allows remote attackers to execute arbitrary code via a long string in a malformed playlist (.m3u) file. NOTE: this may overlap CVE-2008-3408.

Exploits (4)

exploitdb WORKING POC VERIFIED
by His0k4 · pythonlocalwindows
https://www.exploit-db.com/exploits/8520
exploitdb WORKING POC VERIFIED
by Stack · perllocalwindows
https://www.exploit-db.com/exploits/8519
exploitdb WORKING POC VERIFIED
by GoLd_M · perldoswindows
https://www.exploit-db.com/exploits/8489
nomisec WORKING POC 3 stars
by HanseSecure · poc
https://github.com/HanseSecure/CVE-2009-1437

Scores

EPSS 0.0989
EPSS Percentile 93.0%

Details

CWE
CWE-119
Status published
Products (1)
coolplayer/coolplayer 2.19.1
Published Apr 27, 2009
Tracked Since Feb 18, 2026