CVE-2019-25645
WinAVI iPod/3GP/MP4/PSP Converter 4.4.2 contains a denial of service vulnerability that allows local attackers to crash the application by processing malformed AVI files. Attackers can create a specially crafted AVI file with an oversized buffer and load it through the Convert to iPhone function to trigger an application crash.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.9
- CVSS vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.17%
- CWE
- CWE-226
- Published
- 2026-03-24
- Last modified
- 2026-03-24
Affected products
- Winavi WinAVI iPod/3GP/MP4/PSP Converter
Weakness type
Related vulnerabilities
- CVE-2026-18023 — Sensitive Information in Resource Not Removed Before Reuse in ASUS Armoury Crate driver allows a...
- CVE-2026-74791 — Scriban before 7.0.0 Authorization Bypass via Stale Include Cache
- CVE-2026-74250 — In OpenStack Ironic before 38.0.1, the autodetect deploy interface may fail to run cleaning...
- CVE-2026-47247 — libheif Vulnerable to Heap Information Disclosure via Grid Image Gap + Uninitialized Pixel Plane Allocation
- CVE-2026-13585 — Allocation of Resources Without Limits and Throttling and Sensitive Information in Resource Not...
- CVE-2026-48984 — pam_usb: xfree() does not call explicit_bzero — sensitive cryptographic material may linger in freed heap
- CVE-2026-32960 — SD-330AC and AMC Manager provided by silex technology, Inc. contain an issue with a sensitive...
- CVE-2026-5795 — In Eclipse Jetty, the class JASPIAuthenticator initiates the authentication checks, which set two...