CVE-2010-10017
Last modified
CVE-2010-10017 is a high-severity vulnerability rated 8.4/10 on the CVSS scale. WM Downloader version 3.1.2.2 is vulnerable to a buffer overflow when processing a specially crafted .m3u playlist file. The application fails to properly validate input length, allowing an attacker to overwrite structured exception handler (SEH) records and execute arbitrary code. EPSS estimates a 0.30% chance of exploitation in the next 30 days.
Description
WM Downloader version 3.1.2.2 is vulnerable to a buffer overflow when processing a specially crafted .m3u playlist file. The application fails to properly validate input length, allowing an attacker to overwrite structured exception handler (SEH) records and execute arbitrary code. Exploitation occurs locally when a user opens the malicious file, and the payload executes with the privileges of the current user.
Metrics
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2010-10017?
How severe is CVE-2010-10017?
How do I fix CVE-2010-10017?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2010
- CVE-2010-10011A vulnerability, which was classified as problematic, was fo…7.5
- CVE-2010-10012A path traversal vulnerability exists in httpdasm version 0.…8.7
- CVE-2010-10013An unauthenticated remote command execution vulnerability ex…9.3
- CVE-2010-10014Odin Secure FTP <= 4.1 is vulnerable to a stack-based buffer…8.7
- CVE-2010-10015AOL versions up to and including 9.5 includes an ActiveX con…8.4
- CVE-2010-10016BS.Player version 2.57 (build 1051) contains a vulnerability…10
- CVE-2010-1003Directory traversal vulnerability in www/editor/tiny_mce/lan…
- CVE-2010-1004SQL injection vulnerability in the Yet another TYPO3 search …
- CVE-2010-1005Cross-site scripting (XSS) vulnerability in the Yet another …
- CVE-2010-1006SQL injection vulnerability in the Brainstorming extension 0…
- CVE-2010-1007Unspecified vulnerability in the Power Extension Manager (ch…
- CVE-2010-1008Cross-site scripting (XSS) vulnerability in the Sellector.co…
Are you affected by CVE-2010-10017?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
