Product Referenceproduct
https://download.cnet.com/Easy-MP3-Downloader/3000-2141_4-10860695.html CVE-2019-25474
MEDIUM
Easy MP3 Downloader 4.7.8.8 Denial of Service Buffer Overflow
Record summary
CVE-2019-25474 has a selected CVSS score of 6.9 (medium); EIP currently links 1 catalogued exploit.
Description
Easy MP3 Downloader 4.7.8.8 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an excessively long unlock code. Attackers can generate a file containing 6000 'A' characters and paste the contents into the Unlock Code field during application startup to trigger a denial of service condition.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 11, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Easy MP3 Downloader Denial of ServiceDefault status: unaffected | CVE List | 4.7.8.8 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBEasy MP3 Downloader 4.7.8.8 - 'Unlock Code' Denial of ServiceExploitDB exploitby Mohan Ravichandran_ Snazzy SanojNot analyzed1 file
References
5nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-25474 ExploitDB-47319exploit
https://www.exploit-db.com/exploits/47319 vulncheck.com
https://www.vulncheck.com/advisories/easy-mp-downloader-denial-of-service-buffer-overflow VulnCheck Advisory: Easy MP3 Downloader 4.7.8.8 Denial of Service Buffer OverflowThird-party advisory
https://www.vulncheck.com/advisories/easy-mp3-downloader-denial-of-service-buffer-overflow