Videolan

Vlc

11 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.17%
  • Veröffentlicht 29.09.2026 20:01:05
  • Zuletzt bearbeitet 30.09.2026 17:23:08

VLC media player before 3.0.24 contains a path traversal vulnerability in the skins2 ThemeLoader that fails to validate member names in .vlt skin archives. Attackers can craft malicious skin files with path traversal sequences to write arbitrary file...

Exploit
  • EPSS 4.99%
  • Veröffentlicht 28.03.2017 15:59:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

VideoLAN VLC media player before 2.1.5 allows remote attackers to execute arbitrary code or cause a denial of service.

  • EPSS 0.42%
  • Veröffentlicht 12.05.2008 20:20:00
  • Zuletzt bearbeitet 16.06.2026 22:53:11

Untrusted search path vulnerability in VideoLAN VLC before 0.9.0 allows local users to execute arbitrary code via a malicious library under the modules/ or plugins/ subdirectories of the current working directory.

  • EPSS 2.71%
  • Veröffentlicht 25.04.2008 06:05:00
  • Zuletzt bearbeitet 16.06.2026 22:52:27

Multiple integer overflows in VLC before 0.8.6f allow remote attackers to cause a denial of service (crash) via the (1) MP4 demuxer, (2) Real demuxer, and (3) Cinepak codec, which triggers a buffer overflow.

  • EPSS 7.16%
  • Veröffentlicht 25.04.2008 06:05:00
  • Zuletzt bearbeitet 16.06.2026 22:52:27

VLC before 0.8.6f allow remote attackers to cause a denial of service (crash) via a crafted Cinepak file that triggers an out-of-bounds array access and memory corruption.

  • EPSS 11.78%
  • Veröffentlicht 17.04.2008 23:05:00
  • Zuletzt bearbeitet 16.06.2026 22:52:40

Stack-based buffer overflow in the ParseSSA function (modules/demux/subtitle.c) in VLC 0.8.6e allows remote attackers to execute arbitrary code via a long subtitle in an SSA file. NOTE: this issue is due to an incomplete fix for CVE-2007-6681.

Exploit
  • EPSS 11.82%
  • Veröffentlicht 25.03.2008 00:44:00
  • Zuletzt bearbeitet 16.06.2026 22:51:50

Integer overflow in the MP4_ReadBox_rdrf function in libmp4.c for VLC 0.8.6e allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted MP4 RDRF box that triggers a heap-based buffer overflow, a dif...

  • EPSS 17.29%
  • Veröffentlicht 17.01.2008 01:00:00
  • Zuletzt bearbeitet 16.06.2026 22:48:33

Stack-based buffer overflow in modules/demux/subtitle.c in VideoLAN VLC 0.8.6d allows remote attackers to execute arbitrary code via a long subtitle in a (1) MicroDvd, (2) SSA, and (3) Vplayer file.

Exploit
  • EPSS 15.14%
  • Veröffentlicht 17.01.2008 01:00:00
  • Zuletzt bearbeitet 16.06.2026 22:48:34

Format string vulnerability in the httpd_FileCallBack function (network/httpd.c) in VideoLAN VLC 0.8.6d allows remote attackers to execute arbitrary code via format string specifiers in the Connection parameter.

Exploit
  • EPSS 2.78%
  • Veröffentlicht 17.01.2008 01:00:00
  • Zuletzt bearbeitet 16.06.2026 22:48:34

The browser plugin in VideoLAN VLC 0.8.6d allows remote attackers to overwrite arbitrary files via (1) the :demuxdump-file option in a filename in a playlist, or (2) a EXTVLCOPT statement in an MP3 file, possibly an argument injection vulnerability.