Skip to main content

Vendor/product archive

videolan / vlc CVEs

Beta · best-effort

10 CVEs tagged to videolan / vlc1 Critical, 2 High, 7 Medium, 0 Low, 0 Unrated.

CVE-2014-6440

Published Mar 28, 2017

VideoLAN VLC media player before 2.1.5 allows remote attackers to execute arbitrary code or cause a denial of service.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-2147

Published May 12, 2008

Untrusted search path vulnerability in VideoLAN VLC before 0.9.0 allows local users to execute arbitrary code via a malicious library under the modules/ or plugins/ subdirectories…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1768

Published Apr 25, 2008

Multiple integer overflows in VLC before 0.8.6f allow remote attackers to cause a denial of service (crash) via the (1) MP4 demuxer, (2) Real demuxer, and (3) Cinepak codec, which…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1769

Published Apr 25, 2008

VLC before 0.8.6f allow remote attackers to cause a denial of service (crash) via a crafted Cinepak file that triggers an out-of-bounds array access and memory corruption.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1881

Published Apr 17, 2008

Stack-based buffer overflow in the ParseSSA function (modules/demux/subtitle.c) in VLC 0.8.6e allows remote attackers to execute arbitrary code via a long subtitle in an SSA file.…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1489

Published Mar 25, 2008

Integer overflow in the MP4_ReadBox_rdrf function in libmp4.c for VLC 0.8.6e allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6681

Published Jan 17, 2008

Stack-based buffer overflow in modules/demux/subtitle.c in VideoLAN VLC 0.8.6d allows remote attackers to execute arbitrary code via a long subtitle in a (1) MicroDvd, (2) SSA, an…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6682

Published Jan 17, 2008

Format string vulnerability in the httpd_FileCallBack function (network/httpd.c) in VideoLAN VLC 0.8.6d allows remote attackers to execute arbitrary code via format string specifi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6683

Published Jan 17, 2008

The browser plugin in VideoLAN VLC 0.8.6d allows remote attackers to overwrite arbitrary files via (1) the :demuxdump-file option in a filename in a playlist, or (2) a EXTVLCOPT s…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6684

Published Jan 17, 2008

The RTSP module in VideoLAN VLC 0.8.6d allows remote attackers to cause a denial of service (crash) via a request without a Transport parameter, which triggers a NULL pointer dere…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-10 of 10 CVEsPage 1 of 1