CVE-2009-1437

Coolplayer - Memory Corruption

Title source: rule

Description

Stack-based buffer overflow in PortableApps CoolPlayer Portable (aka CoolPlayer+ Portable) 2.19.6 and earlier allows remote attackers to execute arbitrary code via a long string in a malformed playlist (.m3u) file. NOTE: this may overlap CVE-2008-3408.

Exploits (4)

nomisec WORKING POC 3 stars
by HanseSecure · poc
https://github.com/HanseSecure/CVE-2009-1437
exploitdb WORKING POC VERIFIED
by Stack · perllocalwindows
https://www.exploit-db.com/exploits/8519
exploitdb WORKING POC VERIFIED
by GoLd_M · perldoswindows
https://www.exploit-db.com/exploits/8489
exploitdb WORKING POC VERIFIED
by His0k4 · pythonlocalwindows
https://www.exploit-db.com/exploits/8520

Scores

EPSS 0.0989
EPSS Percentile 92.9%

Classification

CWE
CWE-119
Status draft

Affected Products (1)

coolplayer/coolplayer

Timeline

Published Apr 27, 2009
Tracked Since Feb 18, 2026