CVE-2019-25571Disclosure(ventismedia / mediamonkey)

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

MediaMonkey 4.1.23 contains a denial of service vulnerability that allows local attackers to crash the application by opening a specially crafted MP3 file containing an excessively long URL string. Attackers can create a malicious MP3 file with a buffer containing 4000 bytes of data appended to a URL, which causes the application to crash when the file is opened through the File > Open URL dialog.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-226

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mediamonkey

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 1 mentions (2026-03-21); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Products
mediamonkey

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-21: 1Mentions · 2026-03-22: 1Mentions · 2026-05-02: 1Technical Details · 2026-03-21: 1Technical Details · 2026-03-22: 1Technical Details · 2026-05-02: 103-2103-2205-02
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Disclosure

    MediaMonkey 4.1.23 still crashes from CVE-2019-25571. Malicious MP3 with 4000-byte URL triggers classic buffer overflow. Unpatched DoS. #CVE #BufferOverflow #DoS #DevSecOps #DevOps #infosec Info: https://www.valtersit.com/cve/2026/03/cve-2019-25571/

    Post summary

    The post confirms MediaMonkey 4.1.23 is vulnerable to CVE-2019-25571 via a buffer overflow in malicious MP3 files, highlighting a DoS risk without mentioning a fix or exploit code.

    0000043
    889 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2019-25571 MediaMonkey 4.1.23 contains a denial of service vulnerability that allows local attackers to crash the application by opening a specially crafted MP3 file containing … https://www.cve.org/CVERecord?id=CVE-2019-25571

    Post summary

    The post announces a denial‑of‑service flaw in MediaMonkey 4.1.23 that lets local attackers crash the app with a crafted MP3 file, without any PoC, exploit, patch, or evidence of active exploitation.

    0000067
    56.8K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2019-25571 - MediaMonkey 4.1.23 Denial of Service via Malformed URL Intel Report: https://ift.tt/WYCtKsd

    Post summary

    An alert identifies CVE-2019-25571 as a Denial of Service vulnerability in MediaMonkey 4.1.23 triggered by malformed URLs, but no PoC, exploit code, active exploitation, patch, or debunking information is provided.

    0000024
    334 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appventismediamediamonkey4.1.23.1881windows-

Explore more