CVE-2011-10023

CVSS

No CVSS.

M

JM QuickPlayer (likely now referred to as MJM Player) version 2010 contains a stack-based buffer overflow vulnerability triggered by opening a malicious .s3m music file. The flaw occurs due to improper bounds checking in the file parser, allowing an attacker to overwrite memory and execute arbitrary code. Exploitation is achieved via a crafted payload that bypasses DEP and ASLR protections using ROP techniques, and requires user interaction to open the file.

Configurations

No configuration.

History

22 Aug 2025, 18:09

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-20 16:15

Updated : 2025-08-22 18:09


NVD link : CVE-2011-10023

Mitre link : CVE-2011-10023

CVE.ORG link : CVE-2011-10023


JSON object : View

Products Affected

No product.

CWE
CWE-121

Stack-based Buffer Overflow