← Vulnerability feed

Vulnerability record · CVE-2005-2128 · published 12 October 2005

CVE-2005-2128: Microsoft windows media player vulnerability

Microsoft · Windows Media Player

QUARTZ.DLL in Microsoft Windows Media Player 9 allows remote attackers to write a null byte to arbitrary memory via an AVI file with a crafted strn element with a modified length value.

5.0 CVSS 2.0 Medium EPSS 40% · top 1.4%
5.0CVSS 2.0 base score
40%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
30References
16 Jun 2026Last modified by NVD

Description

QUARTZ.DLL in Microsoft Windows Media Player 9 allows remote attackers to write a null byte to arbitrary memory via an AVI file with a crafted strn element with a modified length value.

AV:N/AC:L/Au:N/C:N/I:N/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://secunia.com/advisories/17160
http://secunia.com/advisories/17172
http://secunia.com/advisories/17509
http://support.avaya.com/elmodocs2/security/ASA-2005-214.pdf
http://www.eeye.com/html/research/advisories/AD20051011a.html
http://www.kb.cert.org/vuls/id/995220 US Government Resource
http://www.osvdb.org/18822
http://www.securityfocus.com/bid/15063
http://www.us-cert.gov/cas/techalerts/TA05-284A.html US Government Resource
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-050
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1149
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1231
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1267
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1424
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1434
http://secunia.com/advisories/17160
http://secunia.com/advisories/17172
http://secunia.com/advisories/17509
http://support.avaya.com/elmodocs2/security/ASA-2005-214.pdf
http://www.eeye.com/html/research/advisories/AD20051011a.html
http://www.kb.cert.org/vuls/id/995220 US Government Resource
http://www.osvdb.org/18822
http://www.securityfocus.com/bid/15063
http://www.us-cert.gov/cas/techalerts/TA05-284A.html US Government Resource
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-050
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1149
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1231
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1267
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1424
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1434

Track CVE-2005-2128 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2008-3009Microsoft windows media player vulnerabilityMicrosoft Windows Media Player 6.4, Windows Media Format Runtime 7.1 through 11, and Windows Media Services 4.1, 9, and 2008 do not properly use the …EPSS 16%10.0CVE-2008-3010Microsoft windows media player information exposure vulnerabilityMicrosoft Windows Media Player 6.4, Windows Media Format Runtime 7.1 through 11, and Windows Media Services 4.1 and 9 incorrectly associate ISATAP ad…EPSS 15%10.0CVE-2004-0597libpng PNG chunk buffer overflows allow remote code executionlibpng 1.2.5 and earlier contain multiple buffer overflows in the png_handle_tRNS, png_handle_sBIT and png_handle_hIST functions, which fail to valid…EPSS 83%analysed9.3CVE-2015-1728Microsoft windows media player vulnerabilityMicrosoft Windows Media Player 10 through 12 allows remote attackers to execute arbitrary code via a crafted DataObject on a web site, aka "Windows M…EPSS 18%9.3CVE-2013-3127Microsoft windows media format runtime code injection vulnerabilityThe Microsoft WMV video codec in wmv9vcm.dll, wmvdmod.dll in Windows Media Format Runtime 9 and 9.5, and wmvdecod.dll in Windows Media Format Runtime…EPSS 22%9.3CVE-2010-2745Microsoft windows media player code injection vulnerabilityMicrosoft Windows Media Player (WMP) 9 through 12 does not properly deallocate objects during a browser reload action, which allows user-assisted rem…EPSS 24%9.3CVE-2010-3138Microsoft windows media player vulnerabilityUntrusted search path vulnerability in the Indeo Codec in iac25_32.ax in Microsoft Windows XP SP3 allows local users to gain privileges via a Trojan …EPSS 27%9.3CVE-2010-0268Microsoft windows media player vulnerabilityUnspecified vulnerability in the Windows Media Player ActiveX control in Windows Media Player (WMP) 9 on Microsoft Windows 2000 SP4 and XP SP2 and SP…EPSS 20%

Source: NIST National Vulnerability Database (record CVE-2005-2128), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.