6.8
CVSSv2

CVE-2014-9626

Published: 24/01/2020 Updated: 29/01/2020
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Integer underflow in the MP4_ReadBox_String function in modules/demux/mp4/libmp4.c in VideoLAN VLC media player prior to 2.1.6 allows remote malicious users to cause a denial of service or possibly have unspecified other impact via a box size less than 7.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

videolan vlc media player

Vendor Advisories

Debian Bug report logs - #775866 vlc: multiple vulnerabilities Package: src:vlc; Maintainer for src:vlc is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Reported by: Yves-Alexis Perez <corsac@debianorg> Date: Tue, 20 Jan 2015 20:51:01 UTC Severity: grave Tags: security Found in version vlc/21 ...