← Back

Pandora

pandora

4 CVEs • 2 products

Products (2)

Click to collapse
Toggle
Kmplayer
kmplayer
Pandora
pandora

CVEs (4)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Pandora
1Kmplayer
Jun 17, 2026
Aug 5, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A segmentation fault in KMPlayer v4.2.2.65 allows attackers to cause a Denial of Service (DoS) via a crafted AVI file.
1Pandora
1Kmplayer
Jun 17, 2026
Mar 30, 2023
N/A· v4
7.8 HIGH· v3
4.3 MEDIUM· v2
A vulnerability, which was classified as problematic, has been found in KMPlayer 4.2.2.73. This issue affects some unknown processing in the library SHFOLDER.dll. The manipulation leads to uncontrolled search path. Attac...Show more
A vulnerability, which was classified as problematic, has been found in KMPlayer 4.2.2.73. This issue affects some unknown processing in the library SHFOLDER.dll. The manipulation leads to uncontrolled search path. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The identifier VDB-224633 was assigned to this vulnerability.Show less
1Pandora
1Kmplayer
Nov 21, 2024
Dec 20, 2018
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
KMPlayer 4.2.2.15 and earlier have a Heap Based Buffer Overflow Vulnerability. It could be exploited with a crafted FLV format file. The problem is that more frame data is copied to heap memory than the size specified in...Show more
KMPlayer 4.2.2.15 and earlier have a Heap Based Buffer Overflow Vulnerability. It could be exploited with a crafted FLV format file. The problem is that more frame data is copied to heap memory than the size specified in the frame header. This results in a memory corruption and remote code execution.Show less
1Pandora
1Pandora
May 13, 2026
Dec 16, 2017
N/A· v4
8.1 HIGH· v3
4.3 MEDIUM· v2
Pandora iOS app prior to version 8.3.2 fails to properly validate SSL certificates provided by HTTPS connections, which may enable an attacker to conduct man-in-the-middle (MITM) attacks.