HIGH
AllPlayer 7.4 Local Buffer Overflow via SEH Unicode
Published Jun 4, 2026
8.6
HIGHCVSS 4.0
EPSS 0.15%
Description
AllPlayer 7.4 contains a local buffer overflow vulnerability in URL handling that allows attackers to overwrite structured exception handling pointers by supplying an excessively long URL string. Attackers can craft a malicious URL, paste it into the Open URL dialog, and trigger SEH-based code execution to run arbitrary commands with user privileges.
Affected products
-
- Version 7.4StatusaffectedConstraints-
- Version
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- http://allplayer.org/Download/ALLPlayerEN.exe product
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-20171 Advisory
- https://www.allplayer.org/ product
- https://www.exploit-db.com/exploits/46668 exploit
- https://www.vulncheck.com/advisories/allplayer-local-buffer-overflow-via-seh-unicode third-party-advisory
| Link | Providers | Tags |
|---|---|---|
| http://allplayer.org/Download/ALLPlayerEN.exe | product | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-20171 | Advisory | |
| https://www.allplayer.org/ | product | |
| https://www.exploit-db.com/exploits/46668 | exploit | |
| https://www.vulncheck.com/advisories/allplayer-local-buffer-overflow-via-seh-unicode | third-party-advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Jun 4, 2026
Updated Jul 15, 2026
Reserved Jun 4, 2026
Link CVE-2019-25735
CISA Vulnrichment
Updated Jun 4, 2026
ENISA EUVD
EUVD-2019-20171 Assigner VulnCheck
Published Jun 4, 2026
Updated Jul 15, 2026
Exploited since n/a
Link EUVD-2019-20171