CVE-2018-25251 Details
Description
Snes9K 0.0.9z contains a buffer overflow vulnerability in the Netplay Socket Port Number field that allows local attackers to trigger a structured exception handler (SEH) overwrite. Attackers can craft a malicious payload and paste it into the Socket Port Number field via the Netplay Options menu to achieve code execution through SEH chain exploitation.
A buffer overflow vulnerability has been identified in Snes9K version 0.0.9z, specifically within the Netplay Socket Port Number field. This vulnerability allows local attackers to overwrite the structured exception handler (SEH), potentially leading to code execution. Exploitation involves crafting a malicious payload, which can be pasted into the Socket Port Number field through the Netplay Options menu.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 4, 2026CISA-ADP
Assessed Apr 6, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://sourceforge.net/projects/snes9k/ | [email protected] | ProductVendor |
| https://sourceforge.net/projects/snes9k/files/latest/download | [email protected] | ProductVendor |
| https://www.exploit-db.com/exploits/45598 | [email protected] | Exploit |
| https://www.vulncheck.com/advisories/snes9k-9z-buffer-overflow-seh-via-netplay-socket | [email protected] | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-787 | Out-of-bounds Write | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Snes9K | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 4, 2026 | New CVE Received | [email protected] |
Volerion