Home/Product/kmplayer
Product

kmplayer

10 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2024-41200
all versions
A segmentation fault in KMPlayer v4.2.2.65 allows attackers to cause a Denial of Service (DoS) via a crafted AVI file.
5.5MEDIUM
CVE-2023-1745
all versions
A vulnerability, which was classified as problematic, has been found in KMPlayer 4.2.2.73. This issue affects some unknown process
5.3MEDIUM
CVE-2019-17259
all versions
KMPlayer 4.2.2.31 allows a User Mode Write AV starting at utils!src_new+0x000000000014d6ee.
7.8HIGH
CVE-2019-9133
<= 2018.12.24.14
When processing subtitles format media file, KMPlayer version 2018.12.24.14 or lower doesn't check object size correctly, which le
5.5MEDIUM
CVE-2018-5200
<= 4.2.2.15
KMPlayer 4.2.2.15 and earlier have a Heap Based Buffer Overflow Vulnerability. It could be exploited with a crafted FLV format fil
7.8HIGH
CVE-2017-16952
all versions
KMPlayer 4.2.2.4 allows remote attackers to cause a denial of service via a crafted NSV file.
5.5MEDIUM
CVE-2012-3841
all versions
Untrusted search path vulnerability in KMPlayer 3.2.0.19 allows local users to execute arbitrary code and conduct DLL hijacking at
CVE-2011-2594
all versions
Heap-based buffer overflow in KMPlayer 3.0.0.1441, and possibly other versions, allows remote attackers to execute arbitrary code
CVE-2009-2896
<= 2.9.4.1433
Buffer overflow in KMplayer 2.9.4.1433 and earlier allows remote attackers to cause a denial of service (application crash) or exe
CVE-2007-4941
<= 2.9.3.1210
KMPlayer 2.9.3.1210 and earlier allows remote attackers to cause a denial of service (CPU consumption) via a .avi file with certai
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin