- EPSS 0.3%
- Published 25.09.2024 15:15:14
- Last modified 26.09.2024 13:32:02
VLC media player 3.0.20 and earlier is vulnerable to denial of service through an integer overflow which could be triggered with a maliciously crafted mms stream (heap based overflow). If successful, a malicious third party could trigger either a cra...
CVE-2023-46814
- EPSS 0.11%
- Published 22.11.2023 05:15:07
- Last modified 21.11.2024 08:29:21
A binary hijacking vulnerability exists within the VideoLAN VLC media player before 3.0.19 on Windows. The uninstaller attempts to execute code with elevated privileges out of a standard user writable location. Standard users may use this to gain arb...
CVE-2023-47359
- EPSS 0.13%
- Published 07.11.2023 16:15:29
- Last modified 21.11.2024 08:30:11
Videolan VLC prior to version 3.0.20 contains an incorrect offset read that leads to a Heap-Based Buffer Overflow in function GetPacket() and results in a memory corruption.
CVE-2023-47360
- EPSS 0.09%
- Published 07.11.2023 16:15:29
- Last modified 21.11.2024 08:30:11
Videolan VLC prior to version 3.0.20 contains an Integer underflow that leads to an incorrect packet length.
CVE-2022-41325
- EPSS 0.07%
- Published 06.12.2022 16:15:11
- Last modified 23.04.2025 20:15:41
An integer overflow in the VNC module in VideoLAN VLC Media Player through 3.0.17.4 allows attackers, by tricking a user into opening a crafted playlist or connecting to a rogue VNC server, to crash VLC or execute code under some conditions.
CVE-2021-25801
- EPSS 2.03%
- Published 26.07.2021 17:15:07
- Last modified 21.11.2024 05:55:27
A buffer overflow vulnerability in the __Parse_indx component of VideoLAN VLC Media Player 3.0.11 allows attackers to cause an out-of-bounds read via a crafted .avi file.
CVE-2021-25802
- EPSS 0.28%
- Published 26.07.2021 17:15:07
- Last modified 21.11.2024 05:55:27
A buffer overflow vulnerability in the AVI_ExtractSubtitle component of VideoLAN VLC Media Player 3.0.11 allows attackers to cause an out-of-bounds read via a crafted .avi file.
CVE-2021-25803
- EPSS 0.28%
- Published 26.07.2021 17:15:07
- Last modified 21.11.2024 05:55:27
A buffer overflow vulnerability in the vlc_input_attachment_New component of VideoLAN VLC Media Player 3.0.11 allows attackers to cause an out-of-bounds read via a crafted .avi file.
CVE-2021-25804
- EPSS 1%
- Published 26.07.2021 17:15:07
- Last modified 21.11.2024 05:55:28
A NULL-pointer dereference in "Open" in avi.c of VideoLAN VLC Media Player 3.0.11 can a denial of service (DOS) in the application.
CVE-2020-26664
- EPSS 0.29%
- Published 08.01.2021 18:15:13
- Last modified 21.11.2024 05:20:12
A vulnerability in EbmlTypeDispatcher::send in VideoLAN VLC media player 3.0.11 allows attackers to trigger a heap-based buffer overflow via a crafted .mkv file.