Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
videolan vlc media player vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv2
CVE-2013-6934
The parseRTSPRequestString function in Live Networks Live555 Streaming Media 2013.11.26, as used in VideoLAN VLC Media Player, allows remote malicious users to cause a denial of service (crash) and possibly execute arbitrary code via a space character at the beginning of an RTSP ...
Live555 Streaming Media 2013-11-26
Videolan Vlc Media Player
7.5
CVSSv2
CVE-2013-6283
VideoLAN VLC Media Player 2.0.8 and previous versions allows remote malicious users to cause a denial of service (crash) and possibly execute arbitrary code via a long string in a URL in a m3u file.
Videolan Vlc Media Player
Videolan Vlc Media Player 2.0.1
Videolan Vlc Media Player 2.0.0
Videolan Vlc Media Player 1.1.4
Videolan Vlc Media Player 1.1.3
Videolan Vlc Media Player 1.1.1
Videolan Vlc Media Player 1.1.0
Videolan Vlc Media Player 1.0.0
Videolan Vlc Media Player 2.0.5
Videolan Vlc Media Player 2.0.4
Videolan Vlc Media Player 1.1.7
Videolan Vlc Media Player 1.1.6.1
Videolan Vlc Media Player 1.1.6
Videolan Vlc Media Player 1.1.12
Videolan Vlc Media Player 1.1.11
Videolan Vlc Media Player 1.0.4
Videolan Vlc Media Player 1.0.3
Videolan Vlc Media Player 2.0.3
Videolan Vlc Media Player 2.0.2
Videolan Vlc Media Player 1.1.5
Videolan Vlc Media Player 1.1.4.1
Videolan Vlc Media Player 1.1.10.1
1 EDB exploit
7.5
CVSSv2
CVE-2007-6682
Format string vulnerability in the httpd_FileCallBack function (network/httpd.c) in VideoLAN VLC 0.8.6d allows remote malicious users to execute arbitrary code via format string specifiers in the Connection parameter.
Videolan Vlc
1 EDB exploit
6.8
CVSSv2
CVE-2020-26664
A vulnerability in EbmlTypeDispatcher::send in VideoLAN VLC media player 3.0.11 allows malicious users to trigger a heap-based buffer overflow via a crafted .mkv file.
Videolan Vlc Media Player
Debian Debian Linux 9.0
Debian Debian Linux 10.0
6.8
CVSSv2
CVE-2020-13428
A heap-based buffer overflow in the hxxx_AnnexB_to_xVC function in modules/packetizer/hxxx_nal.c in VideoLAN VLC media player prior to 3.0.11 for macOS/iOS allows remote malicious users to cause a denial of service (application crash) or execute arbitrary code via a crafted H.264...
Videolan Vlc Media Player
Debian Debian Linux 9.0
Debian Debian Linux 10.0
6.8
CVSSv2
CVE-2019-19721
An off-by-one error in the DecodeBlock function in codec/sdl_image.c in VideoLAN VLC media player prior to 3.0.9 allows remote malicious users to cause a denial of service (memory corruption) via a crafted image file. NOTE: this may be related to the SDL_Image product.
Videolan Vlc Media Player
6.8
CVSSv2
CVE-2014-9625
The GetUpdateFile function in misc/update.c in the Updater in VideoLAN VLC media player prior to 2.1.6 performs an incorrect cast operation from a 64-bit integer to a 32-bit integer, which allows remote malicious users to conduct buffer overflow attacks and execute arbitrary code...
Videolan Vlc Media Player
6.8
CVSSv2
CVE-2014-9629
Integer overflow in the Encode function in modules/codec/schroedinger.c in VideoLAN VLC media player prior to 2.1.6 and 2.2.x prior to 2.2.1 allows remote malicious users to conduct buffer overflow attacks and execute arbitrary code via a crafted length value.
Videolan Vlc Media Player
6.8
CVSSv2
CVE-2014-9630
The rtp_packetize_xiph_config function in modules/stream_out/rtpfmt.c in VideoLAN VLC media player prior to 2.1.6 uses a stack-allocation approach with a size determined by arbitrary input data, which allows remote malicious users to cause a denial of service (memory corruption) ...
Videolan Vlc Media Player
6.8
CVSSv2
CVE-2014-9626
Integer underflow in the MP4_ReadBox_String function in modules/demux/mp4/libmp4.c in VideoLAN VLC media player prior to 2.1.6 allows remote malicious users to cause a denial of service or possibly have unspecified other impact via a box size less than 7.
Videolan Vlc Media Player
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-29895
blind SQL injection
CVE-2024-5064
CVE-2023-52677
CVE-2023-52682
CVE-2024-30051
CVE-2024-35849
remote attackers
remote
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
10
NEXT »