HIGHVulnerability
Verified
Global
NVD HIGH: CVE-2019-25689 — HTML5 Video Player 1.2.5 contains a local buffer overflow vulnerability that all...
·Source: NIST NVD
Updated:
Executive Summary
HTML5 Video Player 1.2.5 contains a local buffer overflow vulnerability that allows attackers to execute arbitrary code by supplying an oversized key code string. Attackers can craft a malicious payload exceeding 997 bytes and paste it into the KEY CODE field in the Help Register dialog to trigger code execution and spawn a calculator process.
Analysis
HTML5 Video Player 1.2.5 contains a local buffer overflow vulnerability that allows attackers to execute arbitrary code by supplying an oversized key code string. Attackers can craft a malicious payload exceeding 997 bytes and paste it into the KEY CODE field in the Help Register dialog to trigger code execution and spawn a calculator process. CVSS Score: 8.4. Published: 2026-04-12T13:16:31.923.