CVE-2019-9133 describes an integer underflow vulnerability in KMPlayer versions 2018.12.24.14 and earlier, specifically when processing subtitle media files, leading to memory out-of-bounds read/write. This vulnerability affects KMPlayer across various platforms, including Fedora and Windows. Rated with a CVSS score of 5.5 (Medium), this vulnerability requires user interaction (UI:R) to open a malicious file (AV:L), with low attack complexity (AC:L), and could result in high availability impact (A:H). There is no evidence of active exploitation, nor is exploit code publicly available on platforms like Metasploit or ExploitDB. The vulnerability has garnered minimal community discussion and media coverage, indicating low public awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2018.12.24.14CPE matchmatch criteria | cpe:2.3:a:kmplayer:kmplayer:*:*:*:*:*:*:*:* | ||
29CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:* | ||
30CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.