๐Ÿ” CVE Alert

CVE-2011-10023

UNKNOWN 0.0

MJM QuickPlayer <= 2010 .s3m Stack-Based Buffer Overflow

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

MJM QuickPlayer (likely now referred to as MJM Player) version 2010 contains a stack-based buffer overflow vulnerability triggered by opening a malicious .s3m music file. The flaw occurs due to improper bounds checking in the file parser, allowing an attacker to overwrite memory and execute arbitrary code. Exploitation is achieved via a crafted payload that bypasses DEP and ASLR protections using ROP techniques, and requires user interaction to open the file.

CWE CWE-121
Vendor mjm software
Product quickplayer
Published Aug 20, 2025
Last Updated Apr 7, 2026
Stay Ahead of the Next One

Get instant alerts for mjm software quickplayer

Be the first to know when new unknown vulnerabilities affecting mjm software quickplayer are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

MJM Software / QuickPlayer
2010

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
mjm-software.com: https://mjm-software.com raw.githubusercontent.com: https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/windows/fileformat/mjm_quickplayer_s3m.rb exploit-db.com: https://www.exploit-db.com/exploits/17229 web.archive.org: https://web.archive.org/web/20111016194042/https://www.corelan.be/index.php/forum/security-advisories/corelan-11-003-mjm-quickplayer-2-3-2010-stack-buffer-overflow-s3m/ vulncheck.com: https://www.vulncheck.com/advisories/mjm-quickplayer-s3m-stack-based-buffer-overflow

Credits

rick2600