KMPlayer is a consumer media player with a compact vulnerability footprint centered on video and media file parsing, where disclosed weaknesses cluster around input validation and memory-safety issues including buffer boundary violations and integer arithmetic flaws. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Kmplayer over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-16952MEDIUM KMPlayer 4.2.2.4 allows remote attackers to cause a denial of service via a crafted NSV file. | Nov 28, 2017 | 5.5 | 30 | NO | YES |
CVE-2012-3841HIGH Untrusted search path vulnerability in KMPlayer 3.2.0.19 allows local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse ehtrace.dll that is locat | Jul 3, 2012 | 9.3 | 28 | NO | NO |
CVE-2011-2594HIGH Heap-based buffer overflow in KMPlayer 3.0.0.1441, and possibly other versions, allows remote attackers to execute arbitrary code via a playlist (.KPL) file with a long Title field | Sep 2, 2011 | 9.3 | 28 | NO | NO |
CVE-2019-17259HIGH KMPlayer 4.2.2.31 allows a User Mode Write AV starting at utils!src_new+0x000000000014d6ee. | Oct 8, 2019 | 7.8 | 24 | NO | NO |
CVE-2019-9133MEDIUM When processing subtitles format media file, KMPlayer version 2018.12.24.14 or lower doesn't check object size correctly, which leads to integer underflow then to memory out-of-bou | Apr 9, 2019 | 5.5 | 16 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kmplayer.
Media articles that mention a CVE ID that affects a product developed by Kmplayer — matched by CVE ID, not by vendor name.