Pandora's modest vulnerability footprint centers on its media-streaming platform and the KMPlayer media application, with observed exposure spanning information-disclosure issues, certificate-validation weaknesses, and memory-safety concerns typical of client applications and networked services. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pandora over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-5200HIGH KMPlayer 4.2.2.15 and earlier have a Heap Based Buffer Overflow Vulnerability. It could be exploited with a crafted FLV format file. The problem is that more frame data is copied t | Dec 20, 2018 | 7.8 | 26 | NO | NO |
CVE-2023-1745HIGH A vulnerability, which was classified as problematic, has been found in KMPlayer 4.2.2.73. This issue affects some unknown processing in the library SHFOLDER.dll. The manipulation | Mar 30, 2023 | 7.8 | 24 | NO | NO |
CVE-2018-13144HIGH The transfer and transferFrom functions of a smart contract implementation for Pandora (PDX), an Ethereum token, have an integer overflow. NOTE: this has been disputed by a third p | Jul 4, 2018 | 7.5 | 23 | NO | NO |
CVE-2017-3194HIGH Pandora iOS app prior to version 8.3.2 fails to properly validate SSL certificates provided by HTTPS connections, which may enable an attacker to conduct man-in-the-middle (MITM) a | Dec 16, 2017 | 8.1 | 20 | NO | NO |
CVE-2024-41200MEDIUM A segmentation fault in KMPlayer v4.2.2.65 allows attackers to cause a Denial of Service (DoS) via a crafted AVI file. | Aug 5, 2024 | 5.5 | 18 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pandora.
Media articles that mention a CVE ID that affects a product developed by Pandora — matched by CVE ID, not by vendor name.