CVE-2018-25383
Free MP3 CD Ripper 2.8 Buffer Overflow SEH DEP Bypass
CVSS Score
8.4
EPSS Score
0.0%
EPSS Percentile
0th
Free MP3 CD Ripper 2.8 contains a stack-based buffer overflow vulnerability in WMA file processing that allows local attackers to bypass DEP protection via structured exception handling manipulation. Attackers can craft a malicious WMA file that triggers the overflow when loaded through the Convert function, enabling execution of arbitrary code through ROP chain gadgets and shellcode injection.
| CWE | CWE-121 |
| Vendor | commentcamarche |
| Product | free mp3 cd ripper |
| Published | May 29, 2026 |
| Last Updated | May 29, 2026 |
Stay Ahead of the Next One
Get instant alerts for commentcamarche free mp3 cd ripper
Be the first to know when new high vulnerabilities affecting commentcamarche free mp3 cd ripper are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
Commentcamarche / Free MP3 CD Ripper
2.8
References
Credits
Matteo Malvica