CVE-2010-20111 HIGH

CVE-2010-20111: Digital Music Pad <= 8.2.3.3.4 Stack Buffer Overflow

Vendor Digital Music Pad
Product Digital Music Pad
Weakness CWE-121
Published August 21, 2025
Last update May 15, 2026

CVSS base score

8.4/10
Attack vector Local
Attack complexity Low
Privileges required None
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Digital Music Pad v8.2.3.3.4 contains a stack-based buffer overflow vulnerability in its playlist file parser. When opening a .pls file containing an excessively long string in the File1 field, the application fails to properly validate input length, resulting in corruption of the Structured Exception Handler (SEH) on the stack. This flaw may allow an attacker to control execution flow when the file is opened, potentially leading to arbitrary code execution.

Key dates

02Disclosure timeline

August 21, 2025 CVE published
May 15, 2026 Record updated