CVE-2009-2403

SCMPX 1.5.1 - Heap-Based Buffer Overflow via Long String in M3U Playlist File

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2009-2403. PoCs published by hack4love.

AI-analyzed exploit summary This exploit demonstrates a local heap overflow in SCMPX 1.5.1 by creating a malformed .m3u file with an excessive number of 'A' characters (5000 bytes). The overflow allows control over the ECX and EDX registers, potentially leading to arbitrary code execution.

Description

Heap-based buffer overflow in SCMPX 1.5.1 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a long string in a .m3u playlist file.

Exploits (1)

exploitdb WORKING POC VERIFIED
by hack4love · perldoswindows
https://www.exploit-db.com/exploits/9033

This exploit demonstrates a local heap overflow in SCMPX 1.5.1 by creating a malformed .m3u file with an excessive number of 'A' characters (5000 bytes). The overflow allows control over the ECX and EDX registers, potentially leading to arbitrary code execution.

Classification
Working Poc 90%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: SCMPX 1.5.1
No auth needed
Prerequisites: Local access to the target system · Ability to create a .m3u file
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/9033
Broken Link, Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2009/1729
Broken Link, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/35596

Scores

EPSS 0.0699
EPSS Percentile 93.3%

Details

CWE
CWE-787
Status published
Products (1)
shinjichiba/scmpx 1.5.1
Published Jul 09, 2009
Tracked Since Feb 18, 2026