Vulnerability Details CVE-2009-1087
Multiple argument injection vulnerabilities in PPLive.exe in PPLive 1.9.21 and earlier allow remote attackers to execute arbitrary code via a UNC share pathname in the LoadModule argument to the (1) synacast, (2) Play, (3) pplsv, or (4) ppvod URI handler. NOTE: some of these details are obtained from third party information.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.044
EPSS Ranking 88.6%
CVSS Severity
CVSS v2 Score 9.3
Products affected by CVE-2009-1087
-
cpe:2.3:a:pplive:pplive:*
-
cpe:2.3:a:pplive:pplive:1.9.15