The Pandora Project maintains a narrowly scoped open-source monitoring and alerting platform, with its disclosed vulnerabilities concentrating in the core Pandora product around integer-overflow and numeric-wraparound conditions. This represents a niche vulnerability footprint tied to the platform's arithmetic-heavy data-processing components; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pandora Project over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-5200HIGH KMPlayer 4.2.2.15 and earlier have a Heap Based Buffer Overflow Vulnerability. It could be exploited with a crafted FLV format file. The problem is that more frame data is copied t | Dec 20, 2018 | 7.8 | 26 | NO | NO |
CVE-2023-1745HIGH A vulnerability, which was classified as problematic, has been found in KMPlayer 4.2.2.73. This issue affects some unknown processing in the library SHFOLDER.dll. The manipulation | Mar 30, 2023 | 7.8 | 24 | NO | NO |
CVE-2018-13144HIGH The transfer and transferFrom functions of a smart contract implementation for Pandora (PDX), an Ethereum token, have an integer overflow. NOTE: this has been disputed by a third p | Jul 4, 2018 | 7.5 | 23 | NO | NO |
CVE-2017-3194HIGH Pandora iOS app prior to version 8.3.2 fails to properly validate SSL certificates provided by HTTPS connections, which may enable an attacker to conduct man-in-the-middle (MITM) a | Dec 16, 2017 | 8.1 | 20 | NO | NO |
CVE-2024-41200MEDIUM A segmentation fault in KMPlayer v4.2.2.65 allows attackers to cause a Denial of Service (DoS) via a crafted AVI file. | Aug 5, 2024 | 5.5 | 18 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pandora Project.
Media articles that mention a CVE ID that affects a product developed by Pandora Project — matched by CVE ID, not by vendor name.