Show filters
9 Total Results
Displaying 1-9 of 9
Sort by:
Attacker Value
Unknown

CVE-2023-1745

Disclosure Date: March 30, 2023 (last updated October 08, 2023)
A vulnerability, which was classified as problematic, has been found in KMPlayer 4.2.2.73. This issue affects some unknown processing in the library SHFOLDER.dll. The manipulation leads to uncontrolled search path. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The identifier VDB-224633 was assigned to this vulnerability.
Attacker Value
Unknown

CVE-2019-17259

Disclosure Date: October 08, 2019 (last updated November 27, 2024)
KMPlayer 4.2.2.31 allows a User Mode Write AV starting at utils!src_new+0x000000000014d6ee.
Attacker Value
Unknown

KMPlayer Subtitles parser Heap Overflow Vulnerability

Disclosure Date: April 09, 2019 (last updated November 08, 2023)
When processing subtitles format media file, KMPlayer version 2018.12.24.14 or lower doesn't check object size correctly, which leads to integer underflow then to memory out-of-bound read/write. An attacker can exploit this issue by enticing an unsuspecting user to open a malicious file.
Attacker Value
Unknown

KMPlayer Heap Overflow Vulnerability

Disclosure Date: December 20, 2018 (last updated November 27, 2024)
KMPlayer 4.2.2.15 and earlier have a Heap Based Buffer Overflow Vulnerability. It could be exploited with a crafted FLV format file. The problem is that more frame data is copied to heap memory than the size specified in the frame header. This results in a memory corruption and remote code execution.
Attacker Value
Unknown

CVE-2017-16952

Disclosure Date: November 28, 2017 (last updated November 26, 2024)
KMPlayer 4.2.2.4 allows remote attackers to cause a denial of service via a crafted NSV file.
0
Attacker Value
Unknown

CVE-2012-3841

Disclosure Date: July 03, 2012 (last updated October 04, 2023)
Untrusted search path vulnerability in KMPlayer 3.2.0.19 allows local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse ehtrace.dll that is located in the current working directory.
0
Attacker Value
Unknown

CVE-2011-2594

Disclosure Date: September 02, 2011 (last updated October 04, 2023)
Heap-based buffer overflow in KMPlayer 3.0.0.1441, and possibly other versions, allows remote attackers to execute arbitrary code via a playlist (.KPL) file with a long Title field.
0
Attacker Value
Unknown

CVE-2009-2896

Disclosure Date: August 20, 2009 (last updated October 04, 2023)
Buffer overflow in KMplayer 2.9.4.1433 and earlier allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a long string in a subtitle (.srt) playlist file. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2007-4941

Disclosure Date: September 18, 2007 (last updated October 04, 2023)
KMPlayer 2.9.3.1210 and earlier allows remote attackers to cause a denial of service (CPU consumption) via a .avi file with certain large "indx truck size" and nEntriesInuse values.
0