VYPR

Extended Module Player

by Claudio Matsuoka

CVEs (2)

  • CVE-2007-6731Sep 13, 2009
    risk 0.04cvss epss 0.07

    Extended Module Player (XMP) 2.5.1 and earlier allow remote attackers to execute arbitrary code via an OXM file with a negative value, which bypasses a check in (1) test_oxm and (2) decrunch_oxm functions in misc/oxm.c, leading to a buffer overflow.

  • CVE-2007-6732Sep 13, 2009
    risk 0.00cvss epss 0.04

    Multiple buffer overflows in the dtt_load function in loaders/dtt_load.c Extended Module Player (XMP) 2.5.1 and earlier allow remote attackers to execute arbitrary code via unspecified vectors related to an untrusted length value and the (1) pofs and (2) plen arrays.