CVE-2011-10022
SPlayer version 3.7 and earlier is vulnerable to a stack-based buffer overflow when processing HTTP responses containing an overly long Content-Type header. The vulnerability occurs due to improper bounds checking on the header value, allowing an attacker to overwrite the Structured Exception Handler (SEH) and execute arbitrary code. Exploitation requires the victim to open a media file that triggers an HTTP request to a malicious server, which responds with a crafted Content-Type header.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.6
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 50.13%
- CWE
- CWE-120
- Published
- 2025-08-20
- Last modified
- 2026-05-15
Affected products
- SPlayer Project SPlayer
- SPlayer Project SPlayer
Weakness type
Related vulnerabilities
- CVE-2026-82542 — Tenda HG10 Boa Web Server formIPv6Routing buffer overflow
- CVE-2026-44756 — Memory Corruption vulnerability in SAP Extended Passport (EPP) Processing
- CVE-2026-17040 — Vulnerabilities in IBM AIX and PowerVM VIOS
- CVE-2026-55209 — resdata insufficiently validates untrusted GRDECL files
- CVE-2025-12686 — Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in AdminCenter in Synology BeeStati
- CVE-2026-90608 — Totolink A3002MU boa formPortFw buffer overflow
- CVE-2026-90606 — Totolink A3002MU boa formIpv6Setup buffer overflow
- CVE-2026-90605 — Totolink A3002MU boa formFilter buffer overflow