HIGHVulnerability
Verified
Global

NVD HIGH: CVE-2019-25689 — HTML5 Video Player 1.2.5 contains a local buffer overflow vulnerability that all...

·Source: NIST NVD

Updated:

Executive Summary

HTML5 Video Player 1.2.5 contains a local buffer overflow vulnerability that allows attackers to execute arbitrary code by supplying an oversized key code string. Attackers can craft a malicious payload exceeding 997 bytes and paste it into the KEY CODE field in the Help Register dialog to trigger code execution and spawn a calculator process.

Analysis

HTML5 Video Player 1.2.5 contains a local buffer overflow vulnerability that allows attackers to execute arbitrary code by supplying an oversized key code string. Attackers can craft a malicious payload exceeding 997 bytes and paste it into the KEY CODE field in the Help Register dialog to trigger code execution and spawn a calculator process. CVSS Score: 8.4. Published: 2026-04-12T13:16:31.923.

Indicators of Compromise (1)

CVE (1)
CVE-2019-25689
Source Attribution

Originally published by NIST NVD on Apr 12, 2026. Verified by: NIST.

Related Threats