Gom Player

Vendor:

First CVE: May 1, 2009 · Active for 17 years

9
Total CVEs
More Total CVEs than 86% of tracked products
1.5
Avg CVEs / Year
Higher CVE frequency than 56% of tracked products
7.5
Avg CVSS
Higher Avg CVSS than 59% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Gom Player over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 1, 2009
17 years ago
Most Recent CVE
Dec 15, 2025
221 days ago

CVE Severity & Scoring

Gom Player9 CVEs
All CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local1 (11.1%)
Network2 (22.2%)
Unknown6 (66.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (33.3%)
High0 (0.0%)
Unknown6 (66.7%)
User Interaction
None1 (11.1%)
Unknown6 (66.7%)
Required2 (22.2%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None3 (33.3%)
Unknown6 (66.7%)

Top CVEs

Signals from CVEs in this product scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
GOM Player 2.3.10.5266 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted fpx file.
Feb 21, 20177.839NOYES
Stack-based buffer overflow in GOM Player 2.1.33.5071 allows user-assisted remote attackers to execute arbitrary code via a .ASX file with a long URI in the "ref href" tag. NOTE:
Sep 15, 20129.338NOYES
Stack-based buffer overflow in srt2smi.exe in Gretech Online Movie Player (GOM Player) 2.1.16.4635 allows remote attackers to cause a denial of service (crash) or execute arbitrary
May 1, 20099.335NOYES
GOM Player 2.3.90.5360 contains a buffer overflow vulnerability in the equalizer preset name input field that allows attackers to crash the application. Attackers can overwrite the
Dec 15, 20259.834NONO
Buffer overflow in Gretech GOM Media Player before 2.2.53.5169 has unspecified impact and attack vectors.
Sep 9, 201310.029NONO
GOM Player 2.3.90.5360 contains a remote code execution vulnerability in its Internet Explorer component that allows attackers to execute arbitrary code through DNS spoofing. Attac
Dec 15, 20258.828NONO
Gretech GOM Media Player 2.2.53.5169 and possibly earlier allows remote attackers to cause a denial of service (application crash) via a crafted WAV file.
Sep 9, 20134.325NOYES
Gretech GOM Media Player 2.2.56.5158 and earlier allows remote attackers to cause a denial of service (memory corruption) via a crafted AVI file.
Jan 24, 20144.324NOYES
Gretech GOM Player 2.2.51.5149 and earlier allows remote attackers to cause a denial of service (launch outage) via a crafted image file.
Aug 12, 20144.314NONO

Exploit Exposure

Signals from CVEs in this product scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
5 CVEs
55.6% of CVEs· 93rd percentile

Social Chatter

Signals from CVEs in this product scope (9 CVEs).

Media Mentions

Signals from CVEs in this product scope (9 CVEs).

Top CNAs Publishing CVEs For Gom Player

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2.3.90.536029.30.4%00
2.3.10.526617.88.2%01
2.1.9.375427.22.0%01
2.1.9.375327.22.0%01
2.1.827.22.0%01
2.1.627.22.0%01
2.1.50.514514.32.1%01
2.1.49.513927.22.0%01
2.1.47.513327.22.0%01
2.1.43.511927.22.0%01
2.1.40.510627.22.0%01
2.1.39.510127.22.0%01
2.1.37.508527.22.0%01
2.1.33.507137.93.6%02
2.1.327.22.0%01
2.1.28.503927.22.0%01
2.1.27.503127.22.0%01
2.1.25.501527.22.0%01
2.1.21.484627.22.0%01
2.1.227.22.0%01