CVE-2019-25689

HIGH

HTML5 Video Player 1.2.5 Local Buffer Overflow Non-SEH

Title source: cna
STIX 2.1

Description

HTML5 Video Player 1.2.5 contains a local buffer overflow vulnerability that allows attackers to execute arbitrary code by supplying an oversized key code string. Attackers can craft a malicious payload exceeding 997 bytes and paste it into the KEY CODE field in the Help Register dialog to trigger code execution and spawn a calculator process.

Exploits (1)

exploitdb WORKING POC
by Dino Covotsos · pythonlocalwindows
https://www.exploit-db.com/exploits/46279

Scores

CVSS v3 8.4
EPSS 0.0001
EPSS Percentile 3.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-787
Status published
Products (2)
Html5Videoplayer/HTML5 Video Player 1.2.5
socusoft/html5_video_player 1.2.5
Published Apr 12, 2026
Tracked Since Apr 12, 2026