{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-06-16T06:37:57.898","vulnerabilities":[{"cve":{"id":"CVE-2010-20042","sourceIdentifier":"disclosure@vulncheck.com","published":"2025-08-20T16:15:33.413","lastModified":"2026-05-26T00:16:41.733","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"Xion Audio Player versions 1.0.126 and prior are vulnerable to a Unicode-based stack buffer overflow triggered by opening a specially crafted .m3u playlist file. The file contains an overly long string that overwrites the Structured Exception Handler (SEH) chain, allowing an attacker to hijack execution flow and run arbitrary code."},{"lang":"es","value":"Las versiones de Xion Audio Player anteriores a la 1.0.126 son vulnerables a un desbordamiento de búfer de pila basado en Unicode que se activa al abrir un archivo de lista de reproducción .m3u especialmente manipulado. El archivo contiene una cadena excesivamente larga que sobrescribe la cadena del Gestor de Excepciones Estructuradas (SEH), lo que permite a un atacante secuestrar el flujo de ejecución y ejecutar código arbitrario."}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.4,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"ACTIVE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-121"}]}],"references":[{"url":"https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/windows/fileformat/xion_m3u_sehbof.rb","source":"disclosure@vulncheck.com"},{"url":"https://www.exploit-db.com/exploits/14517","source":"disclosure@vulncheck.com"},{"url":"https://www.exploit-db.com/exploits/14633","source":"disclosure@vulncheck.com"},{"url":"https://www.exploit-db.com/exploits/15598","source":"disclosure@vulncheck.com"},{"url":"https://www.exploit-db.com/exploits/16653","source":"disclosure@vulncheck.com"},{"url":"https://www.r2.com.au/page/products/download/xion-audio-player/","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/xion-audio-player-unicode-stack-buffer-overflow","source":"disclosure@vulncheck.com"}]}}]}