Vulnerability Details CVE-2007-6731
Extended Module Player (XMP) 2.5.1 and earlier allow remote attackers to execute arbitrary code via an OXM file with a negative value, which bypasses a check in (1) test_oxm and (2) decrunch_oxm functions in misc/oxm.c, leading to a buffer overflow.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.068
EPSS Ranking 91.0%
CVSS Severity
CVSS v2 Score 10.0
Products affected by CVE-2007-6731
-
cpe:2.3:a:claudio_matsuoka:extended_module_player:*
-
cpe:2.3:a:claudio_matsuoka:extended_module_player:2.2.0
-
cpe:2.3:a:claudio_matsuoka:extended_module_player:2.2.1
-
cpe:2.3:a:claudio_matsuoka:extended_module_player:2.3.0
-
cpe:2.3:a:claudio_matsuoka:extended_module_player:2.3.1
-
cpe:2.3:a:claudio_matsuoka:extended_module_player:2.3.2
-
cpe:2.3:a:claudio_matsuoka:extended_module_player:2.4.0
-
cpe:2.3:a:claudio_matsuoka:extended_module_player:2.4.1
-
cpe:2.3:a:claudio_matsuoka:extended_module_player:2.5.0