Gomlab's vulnerability profile centers on a modestly represented set of media playback and encoding products, including GOM Player and GOM Media Player, that operate in an accessible consumer-software space. The vendor's disclosures skew toward a meaningful share of serious severity and have a pronounced tendency to acquire public exploit code, reflecting the attack surface presented by media parsers and file-handling routines; the recurring weakness classes include buffer-overflow conditions, improper bounds checking, and cleartext transmission of sensitive data that are characteristic of legacy media software. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gomlab over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-1774HIGH Unspecified vulnerability in the Open URL feature in Gretech GOM Media Player before 2.1.39.5101 has unknown impact and attack vectors, a different vulnerability than CVE-2007-5779 | Mar 18, 2012 | 10.0 | 44 | NO | YES |
CVE-2017-5881HIGH GOM Player 2.3.10.5266 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted fpx file. | Feb 21, 2017 | 7.8 | 39 | NO | YES |
CVE-2011-5162HIGH Stack-based buffer overflow in GOM Player 2.1.33.5071 allows user-assisted remote attackers to execute arbitrary code via a .ASX file with a long URI in the "ref href" tag. NOTE: | Sep 15, 2012 | 9.3 | 38 | NO | YES |
CVE-2009-1022HIGH Heap-based buffer overflow in the Preview/ Set Segment function in Gretech GOMlab GOM Encoder 1.0.0.11 and earlier allows user-assisted remote attackers to cause a denial of servic | Mar 20, 2009 | 9.3 | 36 | NO | YES |
CVE-2009-1497HIGH Stack-based buffer overflow in srt2smi.exe in Gretech Online Movie Player (GOM Player) 2.1.16.4635 allows remote attackers to cause a denial of service (crash) or execute arbitrary | May 1, 2009 | 9.3 | 35 | NO | YES |
CVE-2023-53874CRITICAL GOM Player 2.3.90.5360 contains a buffer overflow vulnerability in the equalizer preset name input field that allows attackers to crash the application. Attackers can overwrite the | Dec 15, 2025 | 9.8 | 34 | NO | NO |
CVE-2012-1264HIGH Unspecified vulnerability in Gretech GOM Media Player before 2.1.37.5091 allows remote attackers to execute arbitrary code via a crafted AVI file. | Mar 18, 2012 | 9.3 | 30 | NO | NO |
CVE-2013-5715HIGH Buffer overflow in Gretech GOM Media Player before 2.2.53.5169 has unspecified impact and attack vectors. | Sep 9, 2013 | 10.0 | 29 | NO | NO |
CVE-2023-53875HIGH GOM Player 2.3.90.5360 contains a remote code execution vulnerability in its Internet Explorer component that allows attackers to execute arbitrary code through DNS spoofing. Attac | Dec 15, 2025 | 8.8 | 28 | NO | NO |
CVE-2013-5716MEDIUM Gretech GOM Media Player 2.2.53.5169 and possibly earlier allows remote attackers to cause a denial of service (application crash) via a crafted WAV file. | Sep 9, 2013 | 4.3 | 25 | NO | YES |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gomlab.
Media articles that mention a CVE ID that affects a product developed by Gomlab — matched by CVE ID, not by vendor name.