Description
BlazeVideo HDTV Player Pro v6.6.0.3 is vulnerable to a stack-based buffer overflow due to improper handling of user-supplied input embedded in .plf playlist files. When parsing a crafted .plf file, the MediaPlayerCtrl.dll component invokes PathFindFileNameA() to extract a filename from a URL-like string. The returned value is then copied to a fixed-size stack buffer using an inline strcpy call without bounds checking. If the input exceeds the buffer size, this leads to a stack overflow and potential arbitrary code execution under the context of the user.
INFO
Published Date :
2025-08-05T20:00:15.915Z
Last Modified :
2026-04-07T14:02:28.500Z
Source :
VulnCheck
AFFECTED PRODUCTS
The following products are affected by CVE-2012-10031 vulnerability.
| Vendors | Products |
|---|---|
| Blazevideo |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2012-10031.