Unrated severityNVD Advisory· Published Sep 13, 2009· Updated Apr 23, 2026
CVE-2007-6732
CVE-2007-6732
Description
Multiple buffer overflows in the dtt_load function in loaders/dtt_load.c Extended Module Player (XMP) 2.5.1 and earlier allow remote attackers to execute arbitrary code via unspecified vectors related to an untrusted length value and the (1) pofs and (2) plen arrays.
Affected products
9cpe:2.3:a:claudio_matsuoka:extended_module_player:*:*:*:*:*:*:*:*+ 8 more
- cpe:2.3:a:claudio_matsuoka:extended_module_player:*:*:*:*:*:*:*:*range: <=2.5.1
- cpe:2.3:a:claudio_matsuoka:extended_module_player:2.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:claudio_matsuoka:extended_module_player:2.2.1:*:*:*:*:*:*:*
- cpe:2.3:a:claudio_matsuoka:extended_module_player:2.3.0:*:*:*:*:*:*:*
- cpe:2.3:a:claudio_matsuoka:extended_module_player:2.3.1:*:*:*:*:*:*:*
- cpe:2.3:a:claudio_matsuoka:extended_module_player:2.3.2:*:*:*:*:*:*:*
- cpe:2.3:a:claudio_matsuoka:extended_module_player:2.4.0:*:*:*:*:*:*:*
- cpe:2.3:a:claudio_matsuoka:extended_module_player:2.4.1:*:*:*:*:*:*:*
- cpe:2.3:a:claudio_matsuoka:extended_module_player:2.5.0:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- aluigi.altervista.org/adv/xmpbof-adv.txtnvdExploit
- www.securityfocus.com/bid/27047nvdExploit
- www.vupen.com/english/advisories/2008/0009nvdVendor Advisory
News mentions
0No linked articles in our index yet.