216.73.216.6

CVE-2019-25689

· Published 12/04/2026 13:16 · Modified 13/04/2026 15:01

Labels: CVE-2019-25689 2026-04-12CVE-2019-25689CWE-787[email protected]

Essential information

Published
12/04/2026 13:16
Modified
13/04/2026 15:01
Author
Creator
CVSS
8.6 HIGH (v3) 8.6 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

HTML5 Video Player 1.2.5 contains a local buffer overflow vulnerability that allows attackers to execute arbitrary code by supplying an oversized key code string. Attackers can craft a malicious payload exceeding 997 bytes and paste it into the KEY CODE field in the Help Register dialog to trigger code execution and spawn a calculator process.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
html5 video player / html5 video player cpe:2.3:a:html5_video_player:html5_video_player:1.2.5:*:*:*:*:*:*:*

References