CVE detail
CVE-2009-1642 — CVE-2009-1642
Published 2009-05-15 · Modified 2026-06-16 · Vendor mini-stream · Product mini-stream_to_mp3_converter · Source nvd
UNKNOWN
severity
CVSS-derived band
0.0686
EPSS probability
exploitation probability, 30d
93.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Multiple stack-based buffer overflows in Mini-stream ASX to MP3 Converter 3.0.0.7 allow remote attackers to execute arbitrary code via (1) a long rtsp URL in a .ram file and (2) a long string in the HREF attribute of a REF element in a .asx file. NOTE: the latter was also subsequently reported in "prior to 3.1.3.7."
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References