Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3x22-75pm-vfvc

Опубликовано: 12 апр. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.6
CVSS3: 8.4

Описание

HTML5 Video Player 1.2.5 contains a local buffer overflow vulnerability that allows attackers to execute arbitrary code by supplying an oversized key code string. Attackers can craft a malicious payload exceeding 997 bytes and paste it into the KEY CODE field in the Help Register dialog to trigger code execution and spawn a calculator process.

HTML5 Video Player 1.2.5 contains a local buffer overflow vulnerability that allows attackers to execute arbitrary code by supplying an oversized key code string. Attackers can craft a malicious payload exceeding 997 bytes and paste it into the KEY CODE field in the Help Register dialog to trigger code execution and spawn a calculator process.

EPSS

Процентиль: 11%
0.00206
Низкий

8.6 High

CVSS4

8.4 High

CVSS3

Дефекты

CWE-787

Связанные уязвимости

CVSS3: 8.4
nvd
5 месяцев назад

HTML5 Video Player 1.2.5 contains a local buffer overflow vulnerability that allows attackers to execute arbitrary code by supplying an oversized key code string. Attackers can craft a malicious payload exceeding 997 bytes and paste it into the KEY CODE field in the Help Register dialog to trigger code execution and spawn a calculator process.

EPSS

Процентиль: 11%
0.00206
Низкий

8.6 High

CVSS4

8.4 High

CVSS3

Дефекты

CWE-787