Allok AVI to DVD SVCD VCD Converter 4.0.1217 contains a structured exception handling (SEH) based buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious string in the License Name field. Attackers can craft a payload with junk data, NSEH bypass, SEH handler address, and shellcode that triggers the overflow when pasted into the License Name field and the Register button is clicked, resulting in code execution.

Project Subscriptions

Vendors Products
Alloksoft Subscribe
Wmv To Avi Mpeg Dvd Wmv Convertor Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 30 Apr 2026 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 29 Apr 2026 20:00:00 +0000

Type Values Removed Values Added
Description Allok AVI to DVD SVCD VCD Converter 4.0.1217 contains a structured exception handling (SEH) based buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious string in the License Name field. Attackers can craft a payload with junk data, NSEH bypass, SEH handler address, and shellcode that triggers the overflow when pasted into the License Name field and the Register button is clicked, resulting in code execution.
Title Allok AVI to DVD SVCD VCD Converter 4.0.1217 Buffer Overflow SEH
First Time appeared Alloksoft
Alloksoft wmv To Avi Mpeg Dvd Wmv Convertor
Weaknesses CWE-120
CPEs cpe:2.3:a:alloksoft:wmv_to_avi_mpeg_dvd_wmv_convertor:4.0.1217:*:*:*:*:*:*:*
Vendors & Products Alloksoft
Alloksoft wmv To Avi Mpeg Dvd Wmv Convertor
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-04-30T12:20:52.131Z

Reserved: 2026-04-29T12:06:12.182Z

Link: CVE-2018-25302

cve-icon Vulnrichment

Updated: 2026-04-30T12:20:47.825Z

cve-icon NVD

Status : Deferred

Published: 2026-04-29T20:16:25.477

Modified: 2026-04-29T21:22:20.120

Link: CVE-2018-25302

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T04:00:15Z

Weaknesses