CVE-2008-4654
- EPSS 77.3%
- Veröffentlicht 22.10.2008 00:11:51
- Zuletzt bearbeitet 09.04.2025 00:30:58
Stack-based buffer overflow in the parse_master function in the Ty demux plugin (modules/demux/ty.c) in VLC Media Player 0.9.0 through 0.9.4 allows remote attackers to execute arbitrary code via a TiVo TY media file with a header containing a crafted...
CVE-2008-4558
- EPSS 19.57%
- Veröffentlicht 15.10.2008 00:00:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Array index error in VLC media player 0.9.2 allows remote attackers to overwrite arbitrary memory and execute arbitrary code via an XSPF playlist file with a negative identifier tag, which passes a signed comparison.
CVE-2008-3794
- EPSS 19.55%
- Veröffentlicht 26.08.2008 15:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Integer signedness error in the mms_ReceiveCommand function in modules/access/mms/mmstu.c in VLC Media Player 0.8.6i allows remote attackers to execute arbitrary code via a crafted mmst link with a negative size value, which bypasses a size check and...
CVE-2008-3732
- EPSS 32.14%
- Veröffentlicht 20.08.2008 16:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Integer overflow in the Open function in modules/demux/tta.c in VLC Media Player 0.8.6i allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted TTA file, which triggers a heap-based bu...
CVE-2008-2430
- EPSS 7.89%
- Veröffentlicht 07.07.2008 23:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Integer overflow in the Open function in modules/demux/wav.c in VLC Media Player 0.8.6h on Windows allows remote attackers to execute arbitrary code via a large fmt chunk in a WAV file.
CVE-2008-0984
- EPSS 26.59%
- Veröffentlicht 26.02.2008 19:44:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The MP4 demuxer (mp4.c) for VLC media player 0.8.6d and earlier, as used in Miro Player 1.1 and earlier, allows remote attackers to overwrite arbitrary memory and execute arbitrary code via a malformed MP4 file.
CVE-2008-0295
- EPSS 32.94%
- Veröffentlicht 16.01.2008 22:00:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Heap-based buffer overflow in modules/access/rtsp/real_sdpplin.c in the Xine library, as used in VideoLAN VLC Media Player 0.8.6d and earlier, allows user-assisted remote attackers to cause a denial of service (crash) or execute arbitrary code via lo...
- EPSS 11.64%
- Veröffentlicht 16.01.2008 22:00:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Heap-based buffer overflow in the libaccess_realrtsp plugin in VideoLAN VLC Media Player 0.8.6d and earlier on Windows might allow remote RTSP servers to cause a denial of service (application crash) or execute arbitrary code via a long string.
CVE-2007-6262
- EPSS 21.73%
- Veröffentlicht 06.12.2007 02:46:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
A certain ActiveX control in axvlc.dll in VideoLAN VLC 0.8.6 before 0.8.6d allows remote attackers to execute arbitrary code via crafted arguments to the (1) addTarget, (2) getVariable, or (3) setVariable function, resulting from a "bad initialized p...
CVE-2007-3467
- EPSS 0.99%
- Veröffentlicht 27.06.2007 22:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Integer overflow in the __status_Update function in stats.c VideoLAN VLC Media Player before 0.8.6c allows remote attackers to cause a denial of service (crash) via a WAV file with a large sample rate.