Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Gomlab

First CVE: Mar 20, 2009Active for: 17 yearsTotal CVEs: 13
50.9
VTI Score
TOP TARGET

Gomlab's vulnerability profile centers on a modestly represented set of media playback and encoding products, including GOM Player and GOM Media Player, that operate in an accessible consumer-software space. The vendor's disclosures skew toward a meaningful share of serious severity and have a pronounced tendency to acquire public exploit code, reflecting the attack surface presented by media parsers and file-handling routines; the recurring weakness classes include buffer-overflow conditions, improper bounds checking, and cleartext transmission of sensitive data that are characteristic of legacy media software. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
13
Total CVEs
More Total CVEs than 94% of tracked vendors
0.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 10% of tracked vendors
7.8
Avg CVSS Score
Higher Avg CVSS Score than 74% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Gomlab over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 20, 2009
17 years ago
Most Recent CVE
Dec 15, 2025
221 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (13 CVEs).

13 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2012-1774HIGH
Unspecified vulnerability in the Open URL feature in Gretech GOM Media Player before 2.1.39.5101 has unknown impact and attack vectors, a different vulnerability than CVE-2007-5779
Mar 18, 201210.044NOYES
CVE-2017-5881HIGH
GOM Player 2.3.10.5266 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted fpx file.
Feb 21, 20177.839NOYES
CVE-2011-5162HIGH
Stack-based buffer overflow in GOM Player 2.1.33.5071 allows user-assisted remote attackers to execute arbitrary code via a .ASX file with a long URI in the "ref href" tag. NOTE:
Sep 15, 20129.338NOYES
CVE-2009-1022HIGH
Heap-based buffer overflow in the Preview/ Set Segment function in Gretech GOMlab GOM Encoder 1.0.0.11 and earlier allows user-assisted remote attackers to cause a denial of servic
Mar 20, 20099.336NOYES
CVE-2009-1497HIGH
Stack-based buffer overflow in srt2smi.exe in Gretech Online Movie Player (GOM Player) 2.1.16.4635 allows remote attackers to cause a denial of service (crash) or execute arbitrary
May 1, 20099.335NOYES
CVE-2023-53874CRITICAL
GOM Player 2.3.90.5360 contains a buffer overflow vulnerability in the equalizer preset name input field that allows attackers to crash the application. Attackers can overwrite the
Dec 15, 20259.834NONO
CVE-2012-1264HIGH
Unspecified vulnerability in Gretech GOM Media Player before 2.1.37.5091 allows remote attackers to execute arbitrary code via a crafted AVI file.
Mar 18, 20129.330NONO
CVE-2013-5715HIGH
Buffer overflow in Gretech GOM Media Player before 2.2.53.5169 has unspecified impact and attack vectors.
Sep 9, 201310.029NONO
CVE-2023-53875HIGH
GOM Player 2.3.90.5360 contains a remote code execution vulnerability in its Internet Explorer component that allows attackers to execute arbitrary code through DNS spoofing. Attac
Dec 15, 20258.828NONO
CVE-2013-5716MEDIUM
Gretech GOM Media Player 2.2.53.5169 and possibly earlier allows remote attackers to cause a denial of service (application crash) via a crafted WAV file.
Sep 9, 20134.325NOYES
View all 13 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products13 CVEs
31%
62%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (7.7%)
Network2 (15.4%)
Unknown10 (76.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (23.1%)
High0 (0.0%)
Unknown10 (76.9%)
User Interaction
None1 (7.7%)
Unknown10 (76.9%)
Required2 (15.4%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None3 (23.1%)
Unknown10 (76.9%)

Exploit Exposure

Signals from CVEs in this vendor scope (13 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
8 CVEs
61.5% of CVEs· 84th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Gomlab.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Gomlab — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Gomlab's Products

View all 3 CNAs →

Top CWEs