CVE-2019-25689: Socusoft HTML5 Video Player
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
HTML5 Video Player 1.2.5 contains a local buffer overflow vulnerability that allows attackers to execute arbitrary code by supplying an oversized key code string. Attackers can craft a malicious payload exceeding 997 bytes and paste it into the KEY CODE field in the Help Register dialog to trigger code execution and spawn a calculator process.
Affected products
- Socusoft HTML5 Video Player: version 1.2.5 only
Published 2026-04-12. Last modified 2026-06-17.