7.8
CVSSv3

CVE-2014-9629

Published: 24/01/2020 Updated: 29/01/2020
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Integer overflow in the Encode function in modules/codec/schroedinger.c in VideoLAN VLC media player prior to 2.1.6 and 2.2.x prior to 2.2.1 allows remote malicious users to conduct buffer overflow attacks and execute arbitrary code via a crafted length value.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

videolan vlc media player

Vendor Advisories

Debian Bug report logs - #775866 vlc: multiple vulnerabilities Package: src:vlc; Maintainer for src:vlc is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Reported by: Yves-Alexis Perez <corsac@debianorg> Date: Tue, 20 Jan 2015 20:51:01 UTC Severity: grave Tags: security Found in version vlc/21 ...