CVE-2019-25735 Details
Description
AllPlayer 7.4 contains a local buffer overflow vulnerability in URL handling that allows attackers to overwrite structured exception handling pointers by supplying an excessively long URL string. Attackers can craft a malicious URL, paste it into the Open URL dialog, and trigger SEH-based code execution to run arbitrary commands with user privileges.
A local buffer overflow vulnerability has been identified in AllPlayer version 7.4. This issue arises in the URL handling process, where an excessively long URL string can overwrite structured exception handling (SEH) pointers. Attackers can exploit this vulnerability by crafting a malicious URL, pasting it into the Open URL dialog, and executing SEH-based code to run arbitrary commands with user privileges.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 4, 2026CISA-ADP
Assessed Jun 4, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://allplayer.org/Download/ALLPlayerEN.exe | [email protected] | Broken LinkProductVendor |
| https://www.allplayer.org/ | [email protected] | Vendor |
| https://www.exploit-db.com/exploits/46668 | [email protected] | Exploit |
| https://www.vulncheck.com/advisories/allplayer-local-buffer-overflow-via-seh-unicode | [email protected] | AdvisoryBundleExploit |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-120 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| AllPlayer | <= 7.4 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 22, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 4, 2026 | New CVE Received | [email protected] |
Volerion