CVE-2007-1559
50Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 32%
from disclosure to weapon0 days
Published on NVDApr 11
1st PoCApr 11
metasploitApr 11
exploitation probability
32%top 2% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
Multiple stack-based buffer overflows in SonicDVDDashVRNav.dll in Roxio CinePlayer 3.2 allow remote attackers to execute arbitrary code via (1) unspecified long property values to SonicMediaPlayer.dll or (2) long arguments to unspecified methods in SonicMediaPlayer.dll.
Affected products
n/a · n/apublic PoCs found — 2
exploitdbwww.exploit-db.com/exploits/16559unverifiedexploitdbwww.exploit-db.com/exploits/29840unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://osvdb.org/34779http://secunia.com/advisories/22251http://secunia.com/secunia_research/2007-46/advisory/https://exchange.xforce.ibmcloud.com/vulnerabilities/33590http://www.securityfocus.com/bid/23412http://www.securitytracker.com/id?1017906http://www.vupen.com/english/advisories/2007/1337