---
id: CVE-2019-25571
title: >-
  MediaMonkey 4.1.23 contains a denial of service vulnerability that allows
  local attackers to crash the application by opening a specially crafted MP3
  file containing an excessively long URL string
summary: >-
  MediaMonkey 4.1.23 contains a denial of service vulnerability that allows
  local attackers to crash the application by opening a specially crafted MP3
  file containing an excessively long URL string. Attackers can create a
  malicious MP3 fi…
severity: medium
cvss: 6.2
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-226
vendor: ventismedia
product: mediamonkey
affected:
  - mediamonkey = 4.1.23.1881
published: '2026-03-21'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T08:10:00.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2019-25571'
references:
  - url: 'https://www.exploit-db.com/exploits/46378'
    label: disclosure@vulncheck.com
  - url: 'https://www.mediamonkey.com/'
    label: disclosure@vulncheck.com
  - url: 'https://www.mediamonkey.com/sw/MediaMonkey_4.1.23.1881.exe'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/mediamonkey-denial-of-service-via-malformed-url
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00178
epssPercentile: 0.06693
ingestedAt: '2026-10-07T08:20:03.903Z'
---

## Overview

MediaMonkey 4.1.23 contains a denial of service vulnerability that allows local attackers to crash the application by opening a specially crafted MP3 file containing an excessively long URL string. Attackers can create a malicious MP3 file with a buffer containing 4000 bytes of data appended to a URL, which causes the application to crash when the file is opened through the File > Open URL dialog.

## Affected

- `mediamonkey = 4.1.23.1881`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
