Kmplayer
by Kmplayer
CVEs (10)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-17259 | Hig | 0.51 | 7.8 | 0.00 | Oct 8, 2019 | KMPlayer 4.2.2.31 allows a User Mode Write AV starting at utils!src_new+0x000000000014d6ee. | ||
| CVE-2018-5200 | Hig | 0.51 | 7.8 | 0.02 | Dec 20, 2018 | KMPlayer 4.2.2.15 and earlier have a Heap Based Buffer Overflow Vulnerability. It could be exploited with a crafted FLV format file. The problem is that more frame data is copied to heap memory than the size specified in the frame header. This results in a memory corruption and… | ||
| CVE-2017-16952 | Med | 0.39 | 5.5 | 0.03 | Nov 28, 2017 | KMPlayer 4.2.2.4 allows remote attackers to cause a denial of service via a crafted NSV file. | ||
| CVE-2024-41200 | Med | 0.36 | 5.5 | 0.00 | Aug 5, 2024 | A segmentation fault in KMPlayer v4.2.2.65 allows attackers to cause a Denial of Service (DoS) via a crafted AVI file. | ||
| CVE-2019-9133 | Med | 0.36 | 5.5 | 0.02 | Apr 9, 2019 | When processing subtitles format media file, KMPlayer version 2018.12.24.14 or lower doesn't check object size correctly, which leads to integer underflow then to memory out-of-bound read/write. An attacker can exploit this issue by enticing an unsuspecting user to open a… | ||
| CVE-2023-1745 | Med | 0.34 | 5.3 | 0.00 | Mar 30, 2023 | A vulnerability, which was classified as problematic, has been found in KMPlayer 4.2.2.73. This issue affects some unknown processing in the library SHFOLDER.dll. The manipulation leads to uncontrolled search path. Attacking locally is a requirement. The exploit has been… | ||
| CVE-2009-2896 | 0.03 | — | 0.06 | Aug 20, 2009 | Buffer overflow in KMplayer 2.9.4.1433 and earlier allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a long string in a subtitle (.srt) playlist file. NOTE: some of these details are obtained from third party information. | |||
| CVE-2007-4941 | 0.03 | — | 0.03 | Sep 18, 2007 | KMPlayer 2.9.3.1210 and earlier allows remote attackers to cause a denial of service (CPU consumption) via a .avi file with certain large "indx truck size" and nEntriesInuse values. | |||
| CVE-2012-3841 | 0.00 | — | 0.03 | Jul 3, 2012 | Untrusted search path vulnerability in KMPlayer 3.2.0.19 allows local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse ehtrace.dll that is located in the current working directory. | |||
| CVE-2011-2594 | 0.00 | — | 0.04 | Sep 2, 2011 | Heap-based buffer overflow in KMPlayer 3.0.0.1441, and possibly other versions, allows remote attackers to execute arbitrary code via a playlist (.KPL) file with a long Title field. |
- risk 0.51cvss 7.8epss 0.00
KMPlayer 4.2.2.31 allows a User Mode Write AV starting at utils!src_new+0x000000000014d6ee.
- risk 0.51cvss 7.8epss 0.02
KMPlayer 4.2.2.15 and earlier have a Heap Based Buffer Overflow Vulnerability. It could be exploited with a crafted FLV format file. The problem is that more frame data is copied to heap memory than the size specified in the frame header. This results in a memory corruption and…
- risk 0.39cvss 5.5epss 0.03
KMPlayer 4.2.2.4 allows remote attackers to cause a denial of service via a crafted NSV file.
- risk 0.36cvss 5.5epss 0.00
A segmentation fault in KMPlayer v4.2.2.65 allows attackers to cause a Denial of Service (DoS) via a crafted AVI file.
- risk 0.36cvss 5.5epss 0.02
When processing subtitles format media file, KMPlayer version 2018.12.24.14 or lower doesn't check object size correctly, which leads to integer underflow then to memory out-of-bound read/write. An attacker can exploit this issue by enticing an unsuspecting user to open a…
- risk 0.34cvss 5.3epss 0.00
A vulnerability, which was classified as problematic, has been found in KMPlayer 4.2.2.73. This issue affects some unknown processing in the library SHFOLDER.dll. The manipulation leads to uncontrolled search path. Attacking locally is a requirement. The exploit has been…
- CVE-2009-2896Aug 20, 2009risk 0.03cvss —epss 0.06
Buffer overflow in KMplayer 2.9.4.1433 and earlier allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a long string in a subtitle (.srt) playlist file. NOTE: some of these details are obtained from third party information.
- CVE-2007-4941Sep 18, 2007risk 0.03cvss —epss 0.03
KMPlayer 2.9.3.1210 and earlier allows remote attackers to cause a denial of service (CPU consumption) via a .avi file with certain large "indx truck size" and nEntriesInuse values.
- CVE-2012-3841Jul 3, 2012risk 0.00cvss —epss 0.03
Untrusted search path vulnerability in KMPlayer 3.2.0.19 allows local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse ehtrace.dll that is located in the current working directory.
- CVE-2011-2594Sep 2, 2011risk 0.00cvss —epss 0.04
Heap-based buffer overflow in KMPlayer 3.0.0.1441, and possibly other versions, allows remote attackers to execute arbitrary code via a playlist (.KPL) file with a long Title field.