High severity8.4NVD Advisory· Published Apr 12, 2026· Updated Apr 17, 2026
CVE-2019-25689
CVE-2019-25689
Description
HTML5 Video Player 1.2.5 contains a local buffer overflow vulnerability that allows attackers to execute arbitrary code by supplying an oversized key code string. Attackers can craft a malicious payload exceeding 997 bytes and paste it into the KEY CODE field in the Help Register dialog to trigger code execution and spawn a calculator process.
Affected products
1- cpe:2.3:a:socusoft:html5_video_player:1.2.5:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.exploit-db.com/exploits/46279nvdExploitVDB Entry
- www.vulncheck.com/advisories/html5-video-player-local-buffer-overflow-non-sehnvdThird Party Advisory
- www.html5videoplayer.net/download.htmlnvdProduct
News mentions
0No linked articles in our index yet.