Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
videolan vulnerabilities and exploits
(subscribe to this query)
7.8
CVSSv3
CVE-2014-9629
Integer overflow in the Encode function in modules/codec/schroedinger.c in VideoLAN VLC media player prior to 2.1.6 and 2.2.x prior to 2.2.1 allows remote malicious users to conduct buffer overflow attacks and execute arbitrary code via a crafted length value.
Videolan Vlc Media Player
NA
CVE-2007-3467
Integer overflow in the __status_Update function in stats.c VideoLAN VLC Media Player prior to 0.8.6c allows remote malicious users to cause a denial of service (crash) via a WAV file with a large sample rate.
Videolan Vlc Media Player
NA
CVE-2007-3468
input.c in VideoLAN VLC Media Player prior to 0.8.6c allows remote malicious users to cause a denial of service (crash) via a crafted WAV file that causes an uninitialized i_nb_resamplers variable to be used.
Videolan Vlc Media Player
7.8
CVSSv3
CVE-2017-9301
plugins\audio_filter\libmpgatofixed32_plugin.dll in VideoLAN VLC media player 2.2.4 allows remote malicious users to cause a denial of service (invalid read and application crash) or possibly have unspecified other impact via a crafted file.
Videolan Vlc Media Player
5.5
CVSSv3
CVE-2017-8313
Heap out-of-bound read in ParseJSS in VideoLAN VLC prior to 2.2.5 due to missing check of string termination allows malicious users to read data beyond allocated memory and potentially crash the process via a crafted subtitles file.
Videolan Vlc Media Player
9.8
CVSSv3
CVE-2019-12874
An issue exists in zlib_decompress_extra in modules/demux/mkv/util.cpp in VideoLAN VLC media player 3.x up to and including 3.0.7. The Matroska demuxer, while parsing a malformed MKV file type, has a double free.
Videolan Vlc Media Player
5.5
CVSSv3
CVE-2019-13615
libebml prior to 1.3.6, as used in the MKV module in VideoLAN VLC Media Player binaries prior to 3.0.3, has a heap-based buffer over-read in EbmlElement::FindNextElement.
Videolan Vlc Media Player
1 Article
5.3
CVSSv3
CVE-2013-3564
The web interface in VideoLAN VLC media player prior to 2.0.7 has no access control which allows remote malicious users to view directory listings via the 'dir' command or issue other commands without authenticating.
Videolan Vlc Media Player
7.8
CVSSv3
CVE-2017-8311
Potential heap based buffer overflow in ParseJSS in VideoLAN VLC prior to 2.2.5 due to skipping NULL terminator in an input string allows malicious users to execute arbitrary code via a crafted subtitles file.
Videolan Vlc Media Player
1 EDB exploit
7.8
CVSSv3
CVE-2019-19721
An off-by-one error in the DecodeBlock function in codec/sdl_image.c in VideoLAN VLC media player prior to 3.0.9 allows remote malicious users to cause a denial of service (memory corruption) via a crafted image file. NOTE: this may be related to the SDL_Image product.
Videolan Vlc Media Player
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-4671
unauthorized
CVE-2024-4776
CVE-2024-3407
CVE-2024-26026
CVE-2024-32888
wireless
CVE-2024-4656
template injection
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
2
3
4
5
6
7
8
9
10
NEXT »