Lyric Video Creator 2.1 contains a denial of service vulnerability that allows attackers to crash the application by processing malformed MP3 files. Attackers can create a crafted MP3 file with an oversized buffer and trigger the crash by opening the file through the Browse song functionality.
History

Thu, 16 Apr 2026 18:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:lyricvideocreator:lyric_video_creator:2.1:*:*:*:*:*:*:*

Mon, 23 Mar 2026 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 23 Mar 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Lyricvideocreator
Lyricvideocreator lyric Video Creator
Vendors & Products Lyricvideocreator
Lyricvideocreator lyric Video Creator

Sat, 21 Mar 2026 13:00:00 +0000

Type Values Removed Values Added
Description Lyric Video Creator 2.1 contains a denial of service vulnerability that allows attackers to crash the application by processing malformed MP3 files. Attackers can create a crafted MP3 file with an oversized buffer and trigger the crash by opening the file through the Browse song functionality.
Title Lyric Video Creator 2.1 Denial of Service via MP3 File
Weaknesses CWE-226
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2026-03-21T12:47:01.399Z

Updated: 2026-03-23T15:39:52.746Z

Reserved: 2026-03-21T12:31:26.076Z

Link: CVE-2019-25560

cve-icon Vulnrichment

Updated: 2026-03-23T15:39:48.366Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-21T13:16:18.957

Modified: 2026-04-16T18:02:42.237

Link: CVE-2019-25560

cve-icon Redhat

No data.