CVE-2020-37065

CRITICAL

StreamRipper32 <2.6 - Buffer Overflow

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2020-37065. PoCs published by Andy Bowden.

AI-analyzed exploit summary This exploit demonstrates a buffer overflow vulnerability in StreamRipper32 2.6 by overwriting the EIP register with a controlled address and executing a calc.exe payload. The PoC generates a malicious input file that triggers the overflow when pasted into the 'SongPattern' field.

Description

StreamRipper32 version 2.6 contains a buffer overflow vulnerability in the Station/Song Section that allows attackers to overwrite memory by manipulating the SongPattern input. Attackers can craft a malicious payload exceeding 256 bytes to potentially execute arbitrary code and compromise the application.

Exploits (1)

exploitdb WORKING POC
by Andy Bowden · pythonlocalwindows
https://www.exploit-db.com/exploits/48517

This exploit demonstrates a buffer overflow vulnerability in StreamRipper32 2.6 by overwriting the EIP register with a controlled address and executing a calc.exe payload. The PoC generates a malicious input file that triggers the overflow when pasted into the 'SongPattern' field.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: StreamRipper32 2.6
No auth needed
Prerequisites: StreamRipper32 2.6 installed on Windows · User interaction to paste the exploit into the 'SongPattern' field
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit, Third Party Advisory exploit
https://www.exploit-db.com/exploits/48517
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/streamripper-buffer-overflow

Scores

CVSS v3 9.8
EPSS 0.0033
EPSS Percentile 24.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-120
Status published
Products (1)
StreamRipper/StreamRipper32 2.6
Published Feb 03, 2026
Tracked Since Feb 18, 2026