← Vulnerability feed

Vulnerability record · CVE-2006-6063 · published 22 November 2006

CVE-2006-6063: XMPlay M3U playlist stack buffer overflow allows remote code execution

Un4seen · Xmplay

Un4seen XMPlay 3.3.0.5 and earlier contains a stack-based buffer overflow triggered by a long FileName field in an M3U playlist file. A long DisplayName field causes a crash. Because the flaw is reachable from a remotely supplied playlist, it can lead to arbitrary code execution on the victim's machine.

7.5 CVSS 2.0 High EPSS 59% · top 0.9%
7.5CVSS 2.0 base score
59%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in Un4seen XMPlay 3.3.0.5 and earlier allows remote attackers to execute arbitrary code via a M3U file containing a long (1) FileName, and cause a crash via a long (2) DisplayName.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityPublic exploit code exists and EPSS is very high, but exploitation requires the user to open a crafted playlist, which limits mass exploitation.

What it is

Un4seen XMPlay 3.3.0.5 and earlier contains a stack-based buffer overflow triggered by a long FileName field in an M3U playlist file. A long DisplayName field causes a crash. Because the flaw is reachable from a remotely supplied playlist, it can lead to arbitrary code execution on the victim's machine.

Impact

An attacker who gets a crafted M3U file opened can execute arbitrary code in the context of the XMPlay process, or at minimum crash it. This gives full control of the affected user's session if code execution succeeds.

Attack surface

Reached by opening a malicious M3U playlist, typically delivered by download, email or a web link. No authentication is required; the only precondition is that the user opens the file, so limited user interaction is needed.

Exploitation

Not listed in CISA KEV, but EPSS is 0.583 (99th percentile) and a public Exploit-DB entry (2815) exists, indicating exploit code is publicly available and exploitation is plausible.

What to do

  • Upgrade XMPlay to a version later than 3.3.0.5, or apply the vendor fix referenced in the Secunia advisory.
  • If upgrade is not possible, block or restrict opening of untrusted M3U files and remove the M3U file association from XMPlay.
  • Filter inbound email and web downloads for M3U attachments and enforce content-type checks at the gateway.
  • Run XMPlay with least privilege and consider application allowlisting to limit the impact of code execution.

Detection

  • Monitor for XMPlay process crashes or abnormal child processes spawned from xmplay.exe.
  • Inspect M3U files for oversized FileName or DisplayName fields before they reach endpoints.
  • Alert on email or web download events involving .m3u files from untrusted sources.
  • Review endpoint logs for code execution originating from the XMPlay process.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2006-6063 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Source: NIST National Vulnerability Database (record CVE-2006-6063), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.