Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
videolan vulnerabilities and exploits
(subscribe to this query)
6.8
CVSSv2
CVE-2020-13428
A heap-based buffer overflow in the hxxx_AnnexB_to_xVC function in modules/packetizer/hxxx_nal.c in VideoLAN VLC media player prior to 3.0.11 for macOS/iOS allows remote malicious users to cause a denial of service (application crash) or execute arbitrary code via a crafted H.264...
Videolan Vlc Media Player
Debian Debian Linux 9.0
Debian Debian Linux 10.0
6.8
CVSSv2
CVE-2019-19721
An off-by-one error in the DecodeBlock function in codec/sdl_image.c in VideoLAN VLC media player prior to 3.0.9 allows remote malicious users to cause a denial of service (memory corruption) via a crafted image file. NOTE: this may be related to the SDL_Image product.
Videolan Vlc Media Player
5
CVSSv2
CVE-2013-3564
The web interface in VideoLAN VLC media player prior to 2.0.7 has no access control which allows remote malicious users to view directory listings via the 'dir' command or issue other commands without authenticating.
Videolan Vlc Media Player
4.3
CVSSv2
CVE-2013-3565
Multiple cross-site scripting (XSS) vulnerabilities in the HTTP Interface in VideoLAN VLC Media Player prior to 2.0.7 allow remote malicious users to inject arbitrary web script or HTML via the (1) command parameter to requests/vlm_cmd.xml, (2) dir parameter to requests/browse.xm...
Videolan Vlc Media Player
Opensuse Opensuse 13.1
6.8
CVSSv2
CVE-2014-9627
The MP4_ReadBox_String function in modules/demux/mp4/libmp4.c in VideoLAN VLC media player prior to 2.1.6 performs an incorrect cast operation from a 64-bit integer to a 32-bit integer, which allows remote malicious users to cause a denial of service or possibly have unspecified ...
Videolan Vlc Media Player
6.8
CVSSv2
CVE-2014-9630
The rtp_packetize_xiph_config function in modules/stream_out/rtpfmt.c in VideoLAN VLC media player prior to 2.1.6 uses a stack-allocation approach with a size determined by arbitrary input data, which allows remote malicious users to cause a denial of service (memory corruption) ...
Videolan Vlc Media Player
6.8
CVSSv2
CVE-2014-9625
The GetUpdateFile function in misc/update.c in the Updater in VideoLAN VLC media player prior to 2.1.6 performs an incorrect cast operation from a 64-bit integer to a 32-bit integer, which allows remote malicious users to conduct buffer overflow attacks and execute arbitrary code...
Videolan Vlc Media Player
6.8
CVSSv2
CVE-2014-9628
The MP4_ReadBox_String function in modules/demux/mp4/libmp4.c in VideoLAN VLC media player prior to 2.1.6 allows remote malicious users to trigger an unintended zero-size malloc and conduct buffer overflow attacks, and consequently execute arbitrary code, via a box size of 7.
Videolan Vlc Media Player
6.8
CVSSv2
CVE-2014-9629
Integer overflow in the Encode function in modules/codec/schroedinger.c in VideoLAN VLC media player prior to 2.1.6 and 2.2.x prior to 2.2.1 allows remote malicious users to conduct buffer overflow attacks and execute arbitrary code via a crafted length value.
Videolan Vlc Media Player
6.8
CVSSv2
CVE-2014-9626
Integer underflow in the MP4_ReadBox_String function in modules/demux/mp4/libmp4.c in VideoLAN VLC media player prior to 2.1.6 allows remote malicious users to cause a denial of service or possibly have unspecified other impact via a box size less than 7.
Videolan Vlc Media Player
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
type confusion
IMAP
CVE-2024-36103
CVE-2024-28995
CVE-2024-37325
CVE-2024-30078
CVE-2024-30082
SQL injection
CVE-2024-30052
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
NEXT »