← Back

Gom Player

gom_player

Vendor: Gomlab • 9 CVEs

CVEs (9)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Gomlab
1Gom Player
Dec 18, 2025
Dec 15, 2025
7.5 HIGH· v4
8.8 HIGH· v3
N/A· v2
GOM Player 2.3.90.5360 contains a remote code execution vulnerability in its Internet Explorer component that allows attackers to execute arbitrary code through DNS spoofing. Attackers can redirect victims using a malici...Show more
GOM Player 2.3.90.5360 contains a remote code execution vulnerability in its Internet Explorer component that allows attackers to execute arbitrary code through DNS spoofing. Attackers can redirect victims using a malicious URL shortcut and WebDAV technique to run a reverse shell with SMB server interaction.Show less
1Gomlab
1Gom Player
Dec 18, 2025
Dec 15, 2025
6.7 MEDIUM· v4
9.8 CRITICAL· v3
N/A· v2
GOM Player 2.3.90.5360 contains a buffer overflow vulnerability in the equalizer preset name input field that allows attackers to crash the application. Attackers can overwrite the preset name with 260 'A' characters to...Show more
GOM Player 2.3.90.5360 contains a buffer overflow vulnerability in the equalizer preset name input field that allows attackers to crash the application. Attackers can overwrite the preset name with 260 'A' characters to trigger a buffer overflow and cause application instability.Show less
1Gomlab
1Gom Player
May 13, 2026
Feb 21, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
GOM Player 2.3.10.5266 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted fpx file.
1Gomlab
1Gom Player
May 6, 2026
Aug 12, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Gretech GOM Player 2.2.51.5149 and earlier allows remote attackers to cause a denial of service (launch outage) via a crafted image file.
1Gomlab
1Gom Player
Apr 29, 2026
Jan 24, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Gretech GOM Media Player 2.2.56.5158 and earlier allows remote attackers to cause a denial of service (memory corruption) via a crafted AVI file.
1Gomlab
1Gom Player
Apr 29, 2026
Sep 9, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Gretech GOM Media Player 2.2.53.5169 and possibly earlier allows remote attackers to cause a denial of service (application crash) via a crafted WAV file.
1Gomlab
1Gom Player
Apr 29, 2026
Sep 9, 2013
N/A· v4
N/A· v3
10.0 HIGH· v2
Buffer overflow in Gretech GOM Media Player before 2.2.53.5169 has unspecified impact and attack vectors.
1Gomlab
1Gom Player
Apr 29, 2026
Sep 15, 2012
N/A· v4
N/A· v3
9.3 HIGH· v2
Stack-based buffer overflow in GOM Player 2.1.33.5071 allows user-assisted remote attackers to execute arbitrary code via a .ASX file with a long URI in the "ref href" tag. NOTE: this issue exists because of a CVE-2007-...Show more
Stack-based buffer overflow in GOM Player 2.1.33.5071 allows user-assisted remote attackers to execute arbitrary code via a .ASX file with a long URI in the "ref href" tag. NOTE: this issue exists because of a CVE-2007-0707 regression.Show less
1Gomlab
1Gom Player
Apr 23, 2026
May 1, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
Stack-based buffer overflow in srt2smi.exe in Gretech Online Movie Player (GOM Player) 2.1.16.4635 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long string in an SRT file.