Windows Media Player
Vendor:
First CVE: Dec 19, 2000 · Active for 25 years
53
Total CVEs
More Total CVEs than 98% of tracked products
3.5
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
7.1
Avg CVSS
Higher Avg CVSS than 43% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Windows Media Player over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 19, 2000
25 years ago
Most Recent CVE
Nov 15, 2017
3,173 days ago
CVE Severity & Scoring
Windows Media Player53 CVEs
32%
64%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local2 (3.8%)
Network0 (0.0%)
Unknown51 (96.2%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (1.9%)
High1 (1.9%)
Unknown51 (96.2%)
User Interaction
None2 (3.8%)
Unknown51 (96.2%)
Required0 (0.0%)
Privileges Required
Low2 (3.8%)
High0 (0.0%)
None0 (0.0%)
Unknown51 (96.2%)
Top CVEs
Signals from CVEs in this product scope (53 CVEs).
53 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-0597HIGH Multiple buffer overflows in libpng 1.2.5 and earlier, as used in multiple products, allow remote attackers to execute arbitrary code via malformed PNG images in which (1) the png_ | Nov 23, 2004 | 10.0 | 81 | NO | YES |
CVE-2006-0006HIGH Heap-based buffer overflow in the bitmap processing routine in Microsoft Windows Media Player 7.1 on Windows 2000 SP4, Media Player 9 on Windows 2000 SP4 and XP SP1, and Media Play | Feb 14, 2006 | 9.3 | 62 | NO | YES |
CVE-2010-2745HIGH Microsoft Windows Media Player (WMP) 9 through 12 does not properly deallocate objects during a browser reload action, which allows user-assisted remote attackers to execute arbitr | Oct 13, 2010 | 9.3 | 53 | NO | YES |
CVE-2003-0228HIGH Directory traversal vulnerability in Microsoft Windows Media Player 7.1 and Windows Media Player for Windows XP allows remote attackers to execute arbitrary code via a skins file w | May 27, 2003 | 7.5 | 53 | NO | YES |
CVE-2010-3138HIGH Untrusted search path vulnerability in the Indeo Codec in iac25_32.ax in Microsoft Windows XP SP3 allows local users to gain privileges via a Trojan horse iacenc.dll file in the cu | Aug 27, 2010 | 9.3 | 52 | NO | YES |
CVE-2014-2671MEDIUM Microsoft Windows Media Player (WMP) 11.0.5721.5230 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted | Mar 31, 2014 | 6.8 | 51 | NO | YES |
CVE-2006-0025HIGH Stack-based buffer overflow in Microsoft Windows Media Player 9 and 10 allows remote attackers to execute arbitrary code via a PNG image with a large chunk size. | Jun 13, 2006 | 9.3 | 51 | NO | NO |
CVE-2007-6401HIGH Stack-based buffer overflow in mplayer2.exe in Microsoft Windows Media Player (WMP) 6.4, when used with the 3ivx 4.5.1 or 5.0.1 codec, allows remote attackers to execute arbitrary | Dec 17, 2007 | 9.3 | 49 | NO | YES |
CVE-2002-1847HIGH Buffer overflow in mplay32.exe of Microsoft Windows Media Player (WMP) 6.3 through 7.1 allows remote attackers to execute arbitrary commands via a long mp3 filename command line ar | Dec 31, 2002 | 7.5 | 46 | NO | YES |
CVE-2009-1331HIGH Integer overflow in Microsoft Windows Media Player (WMP) 11.0.5721.5260 allows remote attackers to cause a denial of service (application crash) via a crafted .mid file, as demonst | Apr 17, 2009 | 9.3 | 44 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (53 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
21 CVEs
39.6% of CVEs· 91st percentile
Social Chatter
Signals from CVEs in this product scope (53 CVEs).
Media Mentions
Signals from CVEs in this product scope (53 CVEs).
Top CNAs Publishing CVEs For Windows Media Player
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9 | 20 | 7.1 | 24.9% | 0 | 7 |
| 8 | 1 | 7.5 | 13.0% | 0 | 0 |
| 7.1 | 8 | 7.0 | 24.7% | 0 | 3 |
| 7 | 11 | 6.3 | 19.2% | 0 | 6 |
| 6.4 | 14 | 7.5 | 20.2% | 0 | 4 |
| 6.3 | 3 | 7.6 | 21.6% | 0 | 1 |
| 12 | 3 | 9.3 | 21.3% | 0 | 1 |
| 11.0.6000.6324 | 2 | 6.8 | 14.0% | 0 | 1 |
| 11.0.5721.5260 | 1 | 9.3 | 18.1% | 0 | 1 |
| 11.0.5721.5230 | 2 | 8.1 | 32.0% | 0 | 1 |
| 11.0.5721.5145 | 3 | 6.0 | 12.3% | 0 | 2 |
| 11 | 11 | 6.5 | 19.1% | 0 | 5 |
| 10.00.00.4036 | 2 | 8.4 | 29.5% | 0 | 0 |
| 10.00.00.4019 | 1 | 9.3 | 17.7% | 0 | 0 |
| 10.00.00.3990 | 1 | 9.3 | 17.7% | 0 | 0 |
| 10.00.00.3646 | 1 | 9.3 | 17.7% | 0 | 0 |
| 10 | 9 | 7.2 | 24.1% | 0 | 3 |