Vulnerabilities
Vulnerable Software
Gomlab:  Security Vulnerabilities
GOM Player 2.3.10.5266 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted fpx file.
CVSS Score
7.8
EPSS Score
0.013
Published
2017-02-21
Gretech GOM Player 2.2.51.5149 and earlier allows remote attackers to cause a denial of service (launch outage) via a crafted image file.
CVSS Score
4.3
EPSS Score
0.007
Published
2014-08-12
GOM Media Player 2.2.57.5189 and earlier allows remote attackers to cause a denial of service (crash) via a crafted .ogg file.
CVSS Score
4.3
EPSS Score
0.075
Published
2014-06-10
Gretech GOM Media Player 2.2.56.5158 and earlier allows remote attackers to cause a denial of service (memory corruption) via a crafted AVI file.
CVSS Score
4.3
EPSS Score
0.081
Published
2014-01-24
Buffer overflow in Gretech GOM Media Player before 2.2.53.5169 has unspecified impact and attack vectors.
CVSS Score
10.0
EPSS Score
0.003
Published
2013-09-09
Gretech GOM Media Player 2.2.53.5169 and possibly earlier allows remote attackers to cause a denial of service (application crash) via a crafted WAV file.
CVSS Score
4.3
EPSS Score
0.093
Published
2013-09-09
Stack-based buffer overflow in GOM Player 2.1.33.5071 allows user-assisted remote attackers to execute arbitrary code via a .ASX file with a long URI in the "ref href" tag. NOTE: this issue exists because of a CVE-2007-0707 regression.
CVSS Score
9.3
EPSS Score
0.36
Published
2012-09-15
Unspecified vulnerability in the Open URL feature in Gretech GOM Media Player before 2.1.39.5101 has unknown impact and attack vectors, a different vulnerability than CVE-2007-5779 and CVE-2012-1264.
CVSS Score
10.0
EPSS Score
0.126
Published
2012-03-18
Unspecified vulnerability in Gretech GOM Media Player before 2.1.37.5091 allows remote attackers to execute arbitrary code via a crafted AVI file.
CVSS Score
9.3
EPSS Score
0.028
Published
2012-03-18
Stack-based buffer overflow in srt2smi.exe in Gretech Online Movie Player (GOM Player) 2.1.16.4635 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long string in an SRT file.
CVSS Score
9.3
EPSS Score
0.109
Published
2009-05-01


Contact Us

Shodan ® - All rights reserved