Allok AVI to DVD SVCD VCD Converter 4.0.1217 contains a structured exception handling (SEH) based buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious string in the License Name field. Attackers can craft a payload with junk data, NSEH bypass, SEH handler address, and shellcode that triggers the overflow when pasted into the License Name field and the Register button is clicked, resulting in code execution.
Metrics
Affected Vendors & Products
References
History
Wed, 29 Apr 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Allok AVI to DVD SVCD VCD Converter 4.0.1217 contains a structured exception handling (SEH) based buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious string in the License Name field. Attackers can craft a payload with junk data, NSEH bypass, SEH handler address, and shellcode that triggers the overflow when pasted into the License Name field and the Register button is clicked, resulting in code execution. | |
| Title | Allok AVI to DVD SVCD VCD Converter 4.0.1217 Buffer Overflow SEH | |
| First Time appeared |
Alloksoft
Alloksoft wmv To Avi Mpeg Dvd Wmv Convertor |
|
| Weaknesses | CWE-120 | |
| CPEs | cpe:2.3:a:alloksoft:wmv_to_avi_mpeg_dvd_wmv_convertor:4.0.1217:*:*:*:*:*:*:* | |
| Vendors & Products |
Alloksoft
Alloksoft wmv To Avi Mpeg Dvd Wmv Convertor |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-04-29T19:24:35.225Z
Updated: 2026-04-29T19:24:35.225Z
Reserved: 2026-04-29T12:06:12.182Z
Link: CVE-2018-25302
No data.
Status : Deferred
Published: 2026-04-29T20:16:25.477
Modified: 2026-04-29T21:22:20.120
Link: CVE-2018-25302
No data.
ReportizFlow