VYPR

VLC media player

by VideoLAN

Source repositories

CVEs (123)

  • CVE-2019-14777HigAug 29, 2019
    risk 0.51cvss 7.8epss 0.02

    The Control function of demux/mkv/mkv.cpp in VideoLAN VLC media player 3.0.7.1 has a use-after-free.

  • CVE-2019-14776HigAug 29, 2019
    risk 0.51cvss 7.8epss 0.02

    A heap-based buffer over-read exists in DemuxInit() in demux/asf/asf.c in VideoLAN VLC media player 3.0.7.1 via a crafted .mkv file.

  • CVE-2019-14533HigAug 29, 2019
    risk 0.51cvss 7.8epss 0.02

    The Control function of demux/asf/asf.c in VideoLAN VLC media player 3.0.7.1 has a use-after-free.

  • CVE-2019-14535HigAug 29, 2019
    risk 0.51cvss 7.8epss 0.02

    A divide-by-zero error exists in the SeekIndex function of demux/asf/asf.c in VideoLAN VLC media player 3.0.7.1. As a result, an FPE can be triggered via a crafted WMV file.

  • CVE-2019-14498HigAug 29, 2019
    risk 0.51cvss 7.8epss 0.02

    A divide-by-zero error exists in the Control function of demux/caf.c in VideoLAN VLC media player 3.0.7.1. As a result, an FPE can be triggered via a crafted CAF file.

  • CVE-2019-14438HigAug 29, 2019
    risk 0.51cvss 7.8epss 0.03

    A heap-based buffer over-read in xiph_PackHeaders() in modules/demux/xiph.h in VideoLAN VLC media player 3.0.7.1 allows remote attackers to trigger a heap-based buffer over-read via a crafted .ogg file.

  • CVE-2019-14437HigAug 29, 2019
    risk 0.51cvss 7.8epss 0.02

    The xiph_SplitHeaders function in modules/demux/xiph.h in VideoLAN VLC media player 3.0.7.1 does not check array bounds properly. As a result, a heap-based buffer over-read can be triggered via a crafted .ogg file.

  • CVE-2019-13602HigJul 14, 2019
    risk 0.51cvss 7.8epss 0.02

    An Integer Underflow in MP4_EIA608_Convert() in modules/demux/mp4/mp4.c in VideoLAN VLC media player through 3.0.7.1 allows remote attackers to cause a denial of service (heap-based buffer overflow and crash) or possibly have unspecified other impact via a crafted .mp4 file.

  • CVE-2017-9301HigMay 29, 2017
    risk 0.51cvss 7.8epss 0.04

    plugins\audio_filter\libmpgatofixed32_plugin.dll in VideoLAN VLC media player 2.2.4 allows remote attackers to cause a denial of service (invalid read and application crash) or possibly have unspecified other impact via a crafted file.

  • CVE-2017-9300HigMay 29, 2017
    risk 0.51cvss 7.8epss 0.05

    plugins\codec\libflac_plugin.dll in VideoLAN VLC media player 2.2.4 allows remote attackers to cause a denial of service (heap corruption and application crash) or possibly have unspecified other impact via a crafted FLAC file.

  • CVE-2023-47360HigNov 7, 2023
    risk 0.49cvss 7.5epss 0.01

    Videolan VLC prior to version 3.0.20 contains an Integer underflow that leads to an incorrect packet length.

  • CVE-2021-25804HigJul 26, 2021
    risk 0.49cvss 7.5epss 0.02

    A NULL-pointer dereference in "Open" in avi.c of VideoLAN VLC Media Player 3.0.11 can a denial of service (DOS) in the application.

  • CVE-2026-56711HigSep 9, 2026
    risk 0.46cvss 7.0epss 0.00

    VLC media player versions 3.0.0 through 3.0.23 contain a memory-safety vulnerability reachable when processing crafted media. Exploitation requires user interaction and may result in application termination or code execution with the privileges of the VLC process.

  • CVE-2021-25803HigJul 26, 2021
    risk 0.46cvss 7.1epss 0.01

    A buffer overflow vulnerability in the vlc_input_attachment_New component of VideoLAN VLC Media Player 3.0.11 allows attackers to cause an out-of-bounds read via a crafted .avi file.

  • CVE-2021-25802HigJul 26, 2021
    risk 0.46cvss 7.1epss 0.01

    A buffer overflow vulnerability in the AVI_ExtractSubtitle component of VideoLAN VLC Media Player 3.0.11 allows attackers to cause an out-of-bounds read via a crafted .avi file.

  • CVE-2021-25801HigJul 26, 2021
    risk 0.46cvss 7.1epss 0.02

    A buffer overflow vulnerability in the __Parse_indx component of VideoLAN VLC Media Player 3.0.11 allows attackers to cause an out-of-bounds read via a crafted .avi file.

  • CVE-2019-5459HigJul 30, 2019
    risk 0.46cvss 7.1epss 0.03

    An Integer underflow in VLC Media Player versions < 3.0.7 leads to an out-of-band read.

  • CVE-2014-9630HigJan 24, 2020
    risk 0.44cvss 7.8epss 0.01

    The rtp_packetize_xiph_config function in modules/stream_out/rtpfmt.c in VideoLAN VLC media player before 2.1.6 uses a stack-allocation approach with a size determined by arbitrary input data, which allows remote attackers to cause a denial of service (memory corruption) or…

  • CVE-2014-9629HigJan 24, 2020
    risk 0.44cvss 7.8epss 0.02

    Integer overflow in the Encode function in modules/codec/schroedinger.c in VideoLAN VLC media player before 2.1.6 and 2.2.x before 2.2.1 allows remote attackers to conduct buffer overflow attacks and execute arbitrary code via a crafted length value.

  • CVE-2014-9628HigJan 24, 2020
    risk 0.44cvss 7.8epss 0.02

    The MP4_ReadBox_String function in modules/demux/mp4/libmp4.c in VideoLAN VLC media player before 2.1.6 allows remote attackers to trigger an unintended zero-size malloc and conduct buffer overflow attacks, and consequently execute arbitrary code, via a box size of 7.

Page 2 of 7