← Back

Kmplayer

kmplayer

Vendor: Kmplayer • 5 CVEs

CVEs (5)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Kmplayer
1Kmplayer
Jun 17, 2026
Oct 8, 2019
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
KMPlayer 4.2.2.31 allows a User Mode Write AV starting at utils!src_new+0x000000000014d6ee.
2Fedoraproject
Kmplayer
2Fedora
Kmplayer
Jun 17, 2026
Apr 9, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
When processing subtitles format media file, KMPlayer version 2018.12.24.14 or lower doesn't check object size correctly, which leads to integer underflow then to memory out-of-bound read/write. An attacker can exploit t...Show more
When processing subtitles format media file, KMPlayer version 2018.12.24.14 or lower doesn't check object size correctly, which leads to integer underflow then to memory out-of-bound read/write. An attacker can exploit this issue by enticing an unsuspecting user to open a malicious file.Show less
1Kmplayer
1Kmplayer
May 13, 2026
Nov 28, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
KMPlayer 4.2.2.4 allows remote attackers to cause a denial of service via a crafted NSV file.
1Kmplayer
1Kmplayer
Apr 29, 2026
Jul 3, 2012
N/A· v4
N/A· v3
9.3 HIGH· v2
Untrusted search path vulnerability in KMPlayer 3.2.0.19 allows local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse ehtrace.dll that is located in the current working directory.
1Kmplayer
1Kmplayer
Apr 29, 2026
Sep 2, 2011
N/A· v4
N/A· v3
9.3 HIGH· v2
Heap-based buffer overflow in KMPlayer 3.0.0.1441, and possibly other versions, allows remote attackers to execute arbitrary code via a playlist (.KPL) file with a long Title field.