Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2013-1868Improper Restriction of Operations within the Bounds of a Memory Buffer in VLC Media Player

Severity
9.3CRITICALNVD
EPSS
50.7%
top 2.14%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedJul 10
Latest updateMay 17

Description

Multiple buffer overflows in VideoLAN VLC media player 2.0.4 and earlier allow remote attackers to cause a denial of service (crash) and execute arbitrary code via vectors related to the (1) freetype renderer and (2) HTML subtitle parser.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages2 packages

🔴Vulnerability Details

3
GHSA
GHSA-cgh8-877w-m8q2: Multiple buffer overflows in VideoLAN VLC media player 22022-05-17
CVEList
CVE-2013-1868: Multiple buffer overflows in VideoLAN VLC media player 22013-07-10
OSV
CVE-2013-1868: Multiple buffer overflows in VideoLAN VLC media player 22013-07-10

💥Exploits & PoCs

1
Exploit-DB
VideoLAN VLC Media Player 2.0.4 - '.swf' Crash (PoC)2012-12-07

📋Vendor Advisories

1
Debian
CVE-2013-1868: vlc - Multiple buffer overflows in VideoLAN VLC media player 2.0.4 and earlier allow r...2013

💬Community

1
Bugzilla
CVE-2013-6424 xorg-x11-server: integer underflow when handling trapezoids2013-12-04
CVE-2013-1868 — Videolan VLC Media Player vulnerability | cvebase