VYPR
Medium severity5.5NVD Advisory· Published Apr 9, 2019· Updated Jun 17, 2026

CVE-2019-9133

CVE-2019-9133

Description

When processing subtitles format media file, KMPlayer version 2018.12.24.14 or lower doesn't check object size correctly, which leads to integer underflow then to memory out-of-bound read/write. An attacker can exploit this issue by enticing an unsuspecting user to open a malicious file.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

5
  • Kmplayer/Kmplayer2 versions
    cpe:2.3:a:kmplayer:kmplayer:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:kmplayer:kmplayer:*:*:*:*:*:*:*:*range: <=2018.12.24.14
    • (no CPE)range: <=2018.12.24.14
  • cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:*
    • cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*
  • Pandora.tv/KMPlayerv5
    Range: KMPlayer

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.