CVE-2017-5881 describes a memory corruption vulnerability in GOM Player version 2.3.10.5266, which can be triggered by a specially crafted .fpx file. This vulnerability carries a high CVSSv3 score of 7.8, indicating a significant risk of denial of service, and potentially other impacts including confidentiality and integrity compromise, requiring user interaction to exploit. While not currently listed on the KEV catalog or Hot List, a public exploit demonstrating denial of service is available on ExploitDB, though there is minimal community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.3.10.5266CPE matchmatch criteria | cpe:2.3:a:gomlab:gom_player:2.3.10.5266:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.