← Vulnerability feed

Vulnerability record · CVE-2006-6251 · published 4 December 2006

CVE-2006-6251: VUPlayer M3U playlist stack buffer overflow enables code execution

Vuplayer · Vuplayer

VUPlayer 2.44 and earlier contains a stack-based buffer overflow triggered by a long string in an M3U playlist file, referred to as an "M3U UNC Name" attack. Opening a crafted playlist can overwrite stack memory and allow arbitrary code execution in the context of the user running the player.

7.5 CVSS 2.0 High EPSS 68% · top 0.7%
7.5CVSS 2.0 base score
68%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
14References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in VUPlayer 2.44 and earlier allows remote attackers to execute arbitrary code via a long string in an M3U file, aka an "M3U UNC Name" attack.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityRemote code execution with public exploit code and a very high EPSS score, though it requires user interaction and affects a legacy media player.

What it is

VUPlayer 2.44 and earlier contains a stack-based buffer overflow triggered by a long string in an M3U playlist file, referred to as an "M3U UNC Name" attack. Opening a crafted playlist can overwrite stack memory and allow arbitrary code execution in the context of the user running the player.

Impact

An attacker who gets a victim to open a malicious M3U file can execute arbitrary code with the privileges of the VUPlayer process, giving full control of the affected host. The CVSS 2.0 vector rates confidentiality, integrity and availability impact as partial.

Attack surface

The flaw is reached remotely over the network through a crafted M3U file, requiring no authentication. It does require user interaction, since the victim must open the playlist in VUPlayer.

Exploitation

Public exploit code exists, as indicated by the SecurityFocus Exploit tag and two Exploit-DB entries. The CVE is not listed in CISA KEV, but EPSS is high at roughly 0.68 (99th percentile), suggesting elevated likelihood of exploitation activity.

What to do

  • Upgrade VUPlayer past 2.44 or remove the product if no fixed version is available, since the record does not name a patched release.
  • Block or strip M3U attachments and downloads at email and web gateways where feasible.
  • Associate M3U files with a hardened or non-privileged handler and avoid opening playlists from untrusted sources.
  • Run VUPlayer with least privilege and apply exploit mitigations such as DEP and ASLR on the host.

Detection

  • Monitor for VUPlayer processes spawning child processes or making unexpected network connections after opening a playlist.
  • Alert on M3U files containing unusually long lines or UNC-style paths written to disk or opened from email and browser download directories.
  • Hunt for crashes or access violations in VUPlayer correlated with recently opened M3U files.
  • Review endpoint logs for VUPlayer execution originating from temp or download folders.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2006-6251 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2006-6251), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.