Windows Media Player

Vendor:

First CVE: Dec 19, 2000 · Active for 25 years

53
Total CVEs
More Total CVEs than 98% of tracked products
3.5
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
7.1
Avg CVSS
Higher Avg CVSS than 43% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Windows Media Player over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 19, 2000
25 years ago
Most Recent CVE
Nov 15, 2017
3,173 days ago

CVE Severity & Scoring

Windows Media Player53 CVEs
All CVEs352,294 CVEs
LowMediumHigh
Attack Vector
Local2 (3.8%)
Network0 (0.0%)
Unknown51 (96.2%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (1.9%)
High1 (1.9%)
Unknown51 (96.2%)
User Interaction
None2 (3.8%)
Unknown51 (96.2%)
Required0 (0.0%)
Privileges Required
Low2 (3.8%)
High0 (0.0%)
None0 (0.0%)
Unknown51 (96.2%)

Top CVEs

Signals from CVEs in this product scope (53 CVEs).

53 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Multiple buffer overflows in libpng 1.2.5 and earlier, as used in multiple products, allow remote attackers to execute arbitrary code via malformed PNG images in which (1) the png_
Nov 23, 200410.081NOYES
Heap-based buffer overflow in the bitmap processing routine in Microsoft Windows Media Player 7.1 on Windows 2000 SP4, Media Player 9 on Windows 2000 SP4 and XP SP1, and Media Play
Feb 14, 20069.362NOYES
Microsoft Windows Media Player (WMP) 9 through 12 does not properly deallocate objects during a browser reload action, which allows user-assisted remote attackers to execute arbitr
Oct 13, 20109.353NOYES
Directory traversal vulnerability in Microsoft Windows Media Player 7.1 and Windows Media Player for Windows XP allows remote attackers to execute arbitrary code via a skins file w
May 27, 20037.553NOYES
Untrusted search path vulnerability in the Indeo Codec in iac25_32.ax in Microsoft Windows XP SP3 allows local users to gain privileges via a Trojan horse iacenc.dll file in the cu
Aug 27, 20109.352NOYES
Microsoft Windows Media Player (WMP) 11.0.5721.5230 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted
Mar 31, 20146.851NOYES
Stack-based buffer overflow in Microsoft Windows Media Player 9 and 10 allows remote attackers to execute arbitrary code via a PNG image with a large chunk size.
Jun 13, 20069.351NONO
Stack-based buffer overflow in mplayer2.exe in Microsoft Windows Media Player (WMP) 6.4, when used with the 3ivx 4.5.1 or 5.0.1 codec, allows remote attackers to execute arbitrary
Dec 17, 20079.349NOYES
Buffer overflow in mplay32.exe of Microsoft Windows Media Player (WMP) 6.3 through 7.1 allows remote attackers to execute arbitrary commands via a long mp3 filename command line ar
Dec 31, 20027.546NOYES
Integer overflow in Microsoft Windows Media Player (WMP) 11.0.5721.5260 allows remote attackers to cause a denial of service (application crash) via a crafted .mid file, as demonst
Apr 17, 20099.344NOYES

Exploit Exposure

Signals from CVEs in this product scope (53 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
21 CVEs
39.6% of CVEs· 91st percentile

Social Chatter

Signals from CVEs in this product scope (53 CVEs).

Media Mentions

Signals from CVEs in this product scope (53 CVEs).

Top CNAs Publishing CVEs For Windows Media Player

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9207.124.9%07
817.513.0%00
7.187.024.7%03
7116.319.2%06
6.4147.520.2%04
6.337.621.6%01
1239.321.3%01
11.0.6000.632426.814.0%01
11.0.5721.526019.318.1%01
11.0.5721.523028.132.0%01
11.0.5721.514536.012.3%02
11116.519.1%05
10.00.00.403628.429.5%00
10.00.00.401919.317.7%00
10.00.00.399019.317.7%00
10.00.00.364619.317.7%00
1097.224.1%03