CVE-2018-16797: Kakaocorp Potplayer

High severity, CVSS 7.8. EPSS: 2.7% chance of exploitation in the next 30 days.

A heap-based buffer overflow in PotPlayerMini.exe in PotPlayer 1.7.8556 allows remote attackers to execute arbitrary code via a .wav file with large BytesPerSec and SamplesPerSec values, and a small Data_Chunk_Size value.

Affected products

Published 2018-09-10. Last modified 2026-06-17.