Nero MediaHome contains an off-by-one overflow condition in the NMMediaServer.dll library that is triggered when parsing header values in overly long HTTP requests. With a specially crafted HTTP request, a remote attacker can cause a single byte heap-based buffer overflow, resulting in a denial of service.