VYPR

Vlc

by VideoLAN

Source repositories

CVEs (37)

  • CVE-2023-47359CriNov 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Videolan VLC prior to version 3.0.20 contains an incorrect offset read that leads to a Heap-Based Buffer Overflow in function GetPacket() and results in a memory corruption.

  • CVE-2014-6440CriMar 28, 2017
    risk 0.64cvss 9.8epss 0.05

    VideoLAN VLC media player before 2.1.5 allows remote attackers to execute arbitrary code or cause a denial of service.

  • CVE-2018-19857CriDec 5, 2018
    risk 0.59cvss 9.1epss 0.04

    The CAF demuxer in modules/demux/caf.c in VideoLAN VLC media player 3.0.4 may read memory from an uninitialized pointer when processing magic cookies in CAF files, because a ReadKukiChunk() cast converts a return value to an unsigned int even if that value is negative. This…

  • CVE-2017-8311HigMay 23, 2017
    risk 0.54cvss 7.8epss 0.09

    Potential heap based buffer overflow in ParseJSS in VideoLAN VLC before 2.2.5 due to skipping NULL terminator in an input string allows attackers to execute arbitrary code via a crafted subtitles file.

  • CVE-2020-13428HigJun 8, 2020
    risk 0.51cvss 7.8epss 0.02

    A heap-based buffer overflow in the hxxx_AnnexB_to_xVC function in modules/packetizer/hxxx_nal.c in VideoLAN VLC media player before 3.0.11 for macOS/iOS allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a crafted H.264…

  • CVE-2019-14970HigAug 29, 2019
    risk 0.51cvss 7.8epss 0.02

    A vulnerability in mkv::event_thread_t in VideoLAN VLC media player 3.0.7.1 allows remote attackers to trigger a heap-based buffer overflow via a crafted .mkv file.

  • CVE-2019-14778HigAug 29, 2019
    risk 0.51cvss 7.8epss 0.01

    The mkv::virtual_segment_c::seek method of demux/mkv/virtual_segment.cpp in VideoLAN VLC media player 3.0.7.1 has a use-after-free.

  • CVE-2019-14777HigAug 29, 2019
    risk 0.51cvss 7.8epss 0.01

    The Control function of demux/mkv/mkv.cpp in VideoLAN VLC media player 3.0.7.1 has a use-after-free.

  • CVE-2019-14776HigAug 29, 2019
    risk 0.51cvss 7.8epss 0.01

    A heap-based buffer over-read exists in DemuxInit() in demux/asf/asf.c in VideoLAN VLC media player 3.0.7.1 via a crafted .mkv file.

  • CVE-2019-14533HigAug 29, 2019
    risk 0.51cvss 7.8epss 0.01

    The Control function of demux/asf/asf.c in VideoLAN VLC media player 3.0.7.1 has a use-after-free.

  • CVE-2019-14535HigAug 29, 2019
    risk 0.51cvss 7.8epss 0.01

    A divide-by-zero error exists in the SeekIndex function of demux/asf/asf.c in VideoLAN VLC media player 3.0.7.1. As a result, an FPE can be triggered via a crafted WMV file.

  • CVE-2019-14498HigAug 29, 2019
    risk 0.51cvss 7.8epss 0.02

    A divide-by-zero error exists in the Control function of demux/caf.c in VideoLAN VLC media player 3.0.7.1. As a result, an FPE can be triggered via a crafted CAF file.

  • CVE-2019-14438HigAug 29, 2019
    risk 0.51cvss 7.8epss 0.02

    A heap-based buffer over-read in xiph_PackHeaders() in modules/demux/xiph.h in VideoLAN VLC media player 3.0.7.1 allows remote attackers to trigger a heap-based buffer over-read via a crafted .ogg file.

  • CVE-2019-13602HigJul 14, 2019
    risk 0.51cvss 7.8epss 0.02

    An Integer Underflow in MP4_EIA608_Convert() in modules/demux/mp4/mp4.c in VideoLAN VLC media player through 3.0.7.1 allows remote attackers to cause a denial of service (heap-based buffer overflow and crash) or possibly have unspecified other impact via a crafted .mp4 file.

  • CVE-2023-47360HigNov 7, 2023
    risk 0.49cvss 7.5epss 0.01

    Videolan VLC prior to version 3.0.20 contains an Integer underflow that leads to an incorrect packet length.

  • CVE-2014-9630HigJan 24, 2020
    risk 0.44cvss 7.8epss 0.01

    The rtp_packetize_xiph_config function in modules/stream_out/rtpfmt.c in VideoLAN VLC media player before 2.1.6 uses a stack-allocation approach with a size determined by arbitrary input data, which allows remote attackers to cause a denial of service (memory corruption) or…

  • CVE-2014-9625HigJan 24, 2020
    risk 0.44cvss 7.8epss 0.02

    The GetUpdateFile function in misc/update.c in the Updater in VideoLAN VLC media player before 2.1.6 performs an incorrect cast operation from a 64-bit integer to a 32-bit integer, which allows remote attackers to conduct buffer overflow attacks and execute arbitrary code via a…

  • CVE-2019-14534MedAug 29, 2019
    risk 0.36cvss 5.5epss 0.01

    In VideoLAN VLC media player 3.0.7.1, there is a NULL pointer dereference at the function SeekPercent of demux/asf/asf.c that will lead to a denial of service attack.

  • CVE-2019-5460MedJul 30, 2019
    risk 0.36cvss 5.5epss 0.03

    Double Free in VLC versions <= 3.0.6 leads to a crash.

  • CVE-2017-8313MedMay 23, 2017
    risk 0.36cvss 5.5epss 0.01

    Heap out-of-bound read in ParseJSS in VideoLAN VLC before 2.2.5 due to missing check of string termination allows attackers to read data beyond allocated memory and potentially crash the process via a crafted subtitles file.

Page 1 of 2