CVE-2011-10023 - CVE House
Back to Database
Status published High CVE-2011-10023

MJM QuickPlayer <= 2010 .s3m Stack-Based Buffer Overflow

Vulnerability Description

MJM QuickPlayer (also known as MJM Player) version 2010 contains a stack-based buffer overflow vulnerability triggered by opening a malicious .s3m music file. The flaw occurs due to improper bounds checking in the file parser, allowing an attacker to overwrite memory and execute arbitrary code. Exploitation is achieved via a crafted payload that bypasses DEP and ASLR protections using ROP techniques, and requires user interaction to open the file.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2011-10023

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • rick2600

Affected Vendor

MJM Software

View all reports →

Affected Software

QuickPlayer
Vulnerable Versions:
2010

Timeline

Official Publish: August 20th, 2025
Last Modified: May 26th, 2026
Added to House: July 19th, 2026

CVSS Vectors

Weaknesses (CWE)