CVE-2009-3807

MixVibes 7.043 Pro - Stack-Based Buffer Overflow via .vib File

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2009-3807. PoCs published by hack4love.

AI-analyzed exploit summary This Perl script generates a malformed .vib file with a large buffer of 'A' characters (5000 bytes) to trigger a local stack overflow in MixVibes Pro 7.043. The exploit writes the payload to 'hack4love.vib', which when opened by the target software, causes a crash due to improper input validation.

Description

Stack-based buffer overflow in MixVibes 7.043 Pro allows remote attackers to cause a denial of service (crash) via a long string in a .vib file.

Exploits (1)

exploitdb WORKING POC VERIFIED
by hack4love · perldoswindows
https://www.exploit-db.com/exploits/9147

This Perl script generates a malformed .vib file with a large buffer of 'A' characters (5000 bytes) to trigger a local stack overflow in MixVibes Pro 7.043. The exploit writes the payload to 'hack4love.vib', which when opened by the target software, causes a crash due to improper input validation.

Classification
Working Poc 90%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: MixVibes Pro 7.043
No auth needed
Prerequisites: Local access to the target system · MixVibes Pro 7.043 installed · Ability to deliver the malicious .vib file to the target
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit, Third Party Advisory exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/9147
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/51715

Scores

EPSS 0.0281
EPSS Percentile 84.7%

Details

CWE
CWE-119
Status published
Products (1)
mixvibes/mixvibes 7.043
Published Oct 27, 2009
Tracked Since Feb 18, 2026