VYPR
Unrated severityNVD Advisory· Published Aug 20, 2010· Updated Apr 29, 2026

CVE-2010-2937

CVE-2010-2937

Description

The ReadMetaFromId3v2 function in taglib.cpp in the TagLib plugin in VideoLAN VLC media player 0.9.0 through 1.1.2 does not properly process ID3v2 tags, which allows remote attackers to cause a denial of service (application crash) via a crafted media file.

Affected products

22
  • cpe:2.3:a:videolan:vlc_media_player:0.9.0:*:*:*:*:*:*:*+ 21 more
    • cpe:2.3:a:videolan:vlc_media_player:0.9.0:*:*:*:*:*:*:*
    • cpe:2.3:a:videolan:vlc_media_player:0.9.1:*:*:*:*:*:*:*
    • cpe:2.3:a:videolan:vlc_media_player:0.9.10:*:*:*:*:*:*:*
    • cpe:2.3:a:videolan:vlc_media_player:0.9.2:*:*:*:*:*:*:*
    • cpe:2.3:a:videolan:vlc_media_player:0.9.3:*:*:*:*:*:*:*
    • cpe:2.3:a:videolan:vlc_media_player:0.9.4:*:*:*:*:*:*:*
    • cpe:2.3:a:videolan:vlc_media_player:0.9.5:*:*:*:*:*:*:*
    • cpe:2.3:a:videolan:vlc_media_player:0.9.6:*:*:*:*:*:*:*
    • cpe:2.3:a:videolan:vlc_media_player:0.9.7:*:*:*:*:*:*:*
    • cpe:2.3:a:videolan:vlc_media_player:0.9.8a:*:*:*:*:*:*:*
    • cpe:2.3:a:videolan:vlc_media_player:0.9.9:*:*:*:*:*:*:*
    • cpe:2.3:a:videolan:vlc_media_player:0.9.9a:*:*:*:*:*:*:*
    • cpe:2.3:a:videolan:vlc_media_player:1.0.0:*:*:*:*:*:*:*
    • cpe:2.3:a:videolan:vlc_media_player:1.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:videolan:vlc_media_player:1.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:videolan:vlc_media_player:1.0.3:*:*:*:*:*:*:*
    • cpe:2.3:a:videolan:vlc_media_player:1.0.4:*:*:*:*:*:*:*
    • cpe:2.3:a:videolan:vlc_media_player:1.0.5:*:*:*:*:*:*:*
    • cpe:2.3:a:videolan:vlc_media_player:1.0.6:*:*:*:*:*:*:*
    • cpe:2.3:a:videolan:vlc_media_player:1.1.0:*:*:*:*:*:*:*
    • cpe:2.3:a:videolan:vlc_media_player:1.1.1:*:*:*:*:*:*:*
    • cpe:2.3:a:videolan:vlc_media_player:1.1.2:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.