Skip to main content

Vendor/product archive

videolan / vlc_media_player CVEs

Beta · best-effort

113 CVEs tagged to videolan / vlc_media_player29 Critical, 47 High, 37 Medium, 0 Low, 0 Unrated.

CVE-2023-47359

Published Nov 7, 2023

Videolan VLC prior to version 3.0.20 contains an incorrect offset read that leads to a Heap-Based Buffer Overflow in function GetPacket() and results in a memory corruption.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-25804

Published Jul 26, 2021

A NULL-pointer dereference in "Open" in avi.c of VideoLAN VLC Media Player 3.0.11 can a denial of service (DOS) in the application.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-25803

Published Jul 26, 2021

A buffer overflow vulnerability in the vlc_input_attachment_New component of VideoLAN VLC Media Player 3.0.11 allows attackers to cause an out-of-bounds read via a crafted .avi fi…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2021-25802

Published Jul 26, 2021

A buffer overflow vulnerability in the AVI_ExtractSubtitle component of VideoLAN VLC Media Player 3.0.11 allows attackers to cause an out-of-bounds read via a crafted .avi file.

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2021-25801

Published Jul 26, 2021

A buffer overflow vulnerability in the __Parse_indx component of VideoLAN VLC Media Player 3.0.11 allows attackers to cause an out-of-bounds read via a crafted .avi file.

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2019-19721

Published May 15, 2020

An off-by-one error in the DecodeBlock function in codec/sdl_image.c in VideoLAN VLC media player before 3.0.9 allows remote attackers to cause a denial of service (memory corrupt…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2013-3564

Published Feb 6, 2020

The web interface in VideoLAN VLC media player before 2.0.7 has no access control which allows remote attackers to view directory listings via the 'dir' command or issue other com…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-3565

Published Jan 31, 2020

Multiple cross-site scripting (XSS) vulnerabilities in the HTTP Interface in VideoLAN VLC Media Player before 2.0.7 allow remote attackers to inject arbitrary web script or HTML v…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-9630

Published Jan 24, 2020

The rtp_packetize_xiph_config function in modules/stream_out/rtpfmt.c in VideoLAN VLC media player before 2.1.6 uses a stack-allocation approach with a size determined by arbitrar…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2014-9629

Published Jan 24, 2020

Integer overflow in the Encode function in modules/codec/schroedinger.c in VideoLAN VLC media player before 2.1.6 and 2.2.x before 2.2.1 allows remote attackers to conduct buffer…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2014-9628

Published Jan 24, 2020

The MP4_ReadBox_String function in modules/demux/mp4/libmp4.c in VideoLAN VLC media player before 2.1.6 allows remote attackers to trigger an unintended zero-size malloc and condu…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2014-9627

Published Jan 24, 2020

The MP4_ReadBox_String function in modules/demux/mp4/libmp4.c in VideoLAN VLC media player before 2.1.6 performs an incorrect cast operation from a 64-bit integer to a 32-bit inte…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2014-9626

Published Jan 24, 2020

Integer underflow in the MP4_ReadBox_String function in modules/demux/mp4/libmp4.c in VideoLAN VLC media player before 2.1.6 allows remote attackers to cause a denial of service o…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2014-9625

Published Jan 24, 2020

The GetUpdateFile function in misc/update.c in the Updater in VideoLAN VLC media player before 2.1.6 performs an incorrect cast operation from a 64-bit integer to a 32-bit integer…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-18278

Published Oct 23, 2019

When executing VideoLAN VLC media player 3.0.8 with libqt on Windows, Data from a Faulting Address controls Code Flow starting at libqt_plugin!vlc_entry_license__3_0_0f+0x00000000…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-14534

Published Aug 29, 2019

In VideoLAN VLC media player 3.0.7.1, there is a NULL pointer dereference at the function SeekPercent of demux/asf/asf.c that will lead to a denial of service attack.

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-25 of 113 CVEsPage 1 of 5