Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2012-0904 — VLC Media Player vulnerability

CWE-3995 documents5 sources
Severity
4.3MEDIUMNVD
EPSS
8.3%
top 7.70%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedJan 20
Latest updateMay 17

Description

VLC media player 1.1.11 allows remote attackers to cause a denial of service (crash) via a long string in an amr file.

CVSS vector

AV:N/AC:M/C:N/I:N/A:PExploitability: 8.6 | Impact: 2.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-jgp8-x56r-6hhp: VLC media player 1↗2022-05-17
â–¶
CVEList
CVE-2012-0904: VLC media player 1↗2012-01-20
â–¶

💥Exploits & PoCs

1
Exploit-DB
VideoLAN VLC Media Player 1.1.11 - '.amr' Denial of Service (PoC)↗2012-01-04
â–¶

📋Vendor Advisories

1
Debian
CVE-2012-0904: vlc - VLC media player 1.1.11 allows remote attackers to cause a denial of service (cr...↗2012
â–¶
CVE-2012-0904 — Videolan VLC Media Player vulnerability | cvebase