WinAVI iPod/3GP/MP4/PSP Converter 4.4.2 contains a denial of service vulnerability that allows local attackers to crash the application by processing malformed AVI files. Attackers can create a specially crafted AVI file with an oversized buffer and load it through the Convert to iPhone function to trigger an application crash.
History

Wed, 25 Mar 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Winavi
Winavi winavi Ipod/3gp/mp4/psp Converter
Vendors & Products Winavi
Winavi winavi Ipod/3gp/mp4/psp Converter

Tue, 24 Mar 2026 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 24 Mar 2026 11:45:00 +0000

Type Values Removed Values Added
Description WinAVI iPod/3GP/MP4/PSP Converter 4.4.2 contains a denial of service vulnerability that allows local attackers to crash the application by processing malformed AVI files. Attackers can create a specially crafted AVI file with an oversized buffer and load it through the Convert to iPhone function to trigger an application crash.
Title WinAVI iPod 3GP MP4 PSP Converter 4.4.2 Denial of Service
Weaknesses CWE-226
References
Metrics cvssV3_1

{'score': 6.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2026-03-24T11:27:15.914Z

Updated: 2026-03-24T13:00:53.933Z

Reserved: 2026-03-24T11:06:14.608Z

Link: CVE-2019-25645

cve-icon Vulnrichment

Updated: 2026-03-24T12:58:58.432Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-03-24T12:16:07.030

Modified: 2026-03-24T15:53:48.067

Link: CVE-2019-25645

cve-icon Redhat

No data.