cbcvebase.

Debian Vlc vulnerabilities

122 known vulnerabilities affecting debian/vlc.

Total CVEs
122
CISA KEV
0
Public exploits
33
Exploited in wild
0
Severity breakdown
CRITICAL14HIGH44MEDIUM41LOW23

Vulnerabilities

Page 1 of 7
CVE-2010-3275P2CRITICALCVSS 9.3PoCfixed in vlc 1.1.8-1 (bookworm)2010
CVE-2010-3275 [CRITICAL] CVE-2010-3275: vlc - libdirectx_plugin.dll in VideoLAN VLC Media Player before 1.1.8 allows remote at... libdirectx_plugin.dll in VideoLAN VLC Media Player before 1.1.8 allows remote attackers to execute arbitrary code via a crafted width in an AMV file, related to a "dangling pointer vulnerability." Scope: local bookworm: resolved (fixed in 1.1.8-1) bullseye: resolved (fixed in 1.1.8-1) forky: resolved (fixed in 1.1.8-1) sid: resolved (fixed in 1.1.8-1) trixie: resolved
debian
CVE-2008-4654P2LOWCVSS 9.3PoCfixed in vlc 1.0.3-1 (bookworm)2008
CVE-2008-4654 [CRITICAL] CVE-2008-4654: vlc - Stack-based buffer overflow in the parse_master function in the Ty demux plugin ... Stack-based buffer overflow in the parse_master function in the Ty demux plugin (modules/demux/ty.c) in VLC Media Player 0.9.0 through 0.9.4 allows remote attackers to execute arbitrary code via a TiVo TY media file with a header containing a crafted size value. Scope: local bookworm: resolved (fixed in 1.0.3-1) bullseye: resolved (fixed in 1.0.3-1) forky: resolved (f
debian
CVE-2012-1775P2LOWCVSS 9.3PoCfixed in vlc 2.0.1-1 (bookworm)2012
CVE-2012-1775 [CRITICAL] CVE-2012-1775: vlc - Stack-based buffer overflow in VideoLAN VLC media player before 2.0.1 allows rem... Stack-based buffer overflow in VideoLAN VLC media player before 2.0.1 allows remote attackers to execute arbitrary code via a crafted MMS:// stream. Scope: local bookworm: resolved (fixed in 2.0.1-1) bullseye: resolved (fixed in 2.0.1-1) forky: resolved (fixed in 2.0.1-1) sid: resolved (fixed in 2.0.1-1) trixie: resolved (fixed in 2.0.1-1)
debian
CVE-2011-0531P2MEDIUMCVSS 9.3PoCfixed in vlc 1.1.7-1 (bookworm)2011
CVE-2011-0531 [CRITICAL] CVE-2011-0531: vlc - demux/mkv/mkv.hpp in the MKV demuxer plugin in VideoLAN VLC media player 1.1.6.1... demux/mkv/mkv.hpp in the MKV demuxer plugin in VideoLAN VLC media player 1.1.6.1 and earlier allows remote attackers to cause a denial of service (crash) and execute arbitrary commands via a crafted MKV (WebM or Matroska) file that triggers memory corruption, related to "class mismatching" and the MKV_IS_ID macro. Scope: local bookworm: resolved (fixed in 1.1.7-1) bul
debian
CVE-2016-5108P2CRITICALCVSS 9.8PoCfixed in vlc 2.2.3-2 (bookworm)2016
CVE-2016-5108 [CRITICAL] CVE-2016-5108: vlc - Buffer overflow in the DecodeAdpcmImaQT function in modules/codec/adpcm.c in Vid... Buffer overflow in the DecodeAdpcmImaQT function in modules/codec/adpcm.c in VideoLAN VLC media player before 2.2.4 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted QuickTime IMA file. Scope: local bookworm: resolved (fixed in 2.2.3-2) bullseye: resolved (fixed in 2.2.3-2) forky: resolved (fixed in 2.2.3-2)
debian
CVE-2011-0522P2MEDIUMCVSS 6.8PoCfixed in vlc 1.1.3-1squeeze2 (bookworm)2011
CVE-2011-0522 [MEDIUM] CVE-2011-0522: vlc - The StripTags function in (1) the USF decoder (modules/codec/subtitles/subsdec.c... The StripTags function in (1) the USF decoder (modules/codec/subtitles/subsdec.c) and (2) the Text decoder (modules/codec/subtitles/subsusf.c) in VideoLAN VLC Media Player 1.1 before 1.1.6-rc allows remote attackers to execute arbitrary code via a subtitle with an opening "" in an MKV file, which triggers heap memory corruption, as demonstrated using refined-australia-b
debian
CVE-2018-11529P2HIGHCVSS 8.0PoCfixed in vlc 3.0.3-1-1 (bookworm)2018
CVE-2018-11529 [HIGH] CVE-2018-11529: vlc - VideoLAN VLC media player 2.2.x is prone to a use after free vulnerability which... VideoLAN VLC media player 2.2.x is prone to a use after free vulnerability which an attacker can leverage to execute arbitrary code via crafted MKV files. Failed exploit attempts will likely result in denial of service conditions. Scope: local bookworm: resolved (fixed in 3.0.3-1-1) bullseye: resolved (fixed in 3.0.3-1-1) forky: resolved (fixed in 3.0.3-1-1) sid: resolv
debian
CVE-2008-5036P3LOWCVSS 9.3PoCfixed in vlc 1.0.3-1 (bookworm)2008
CVE-2008-5036 [CRITICAL] CVE-2008-5036: vlc - Stack-based buffer overflow in VideoLAN VLC media player 0.9.x before 0.9.6 migh... Stack-based buffer overflow in VideoLAN VLC media player 0.9.x before 0.9.6 might allow user-assisted attackers to execute arbitrary code via an an invalid RealText (rt) subtitle file, related to the ParseRealText function in modules/demux/subtitle.c. NOTE: this issue was SPLIT from CVE-2008-5032 on 20081110. Scope: local bookworm: resolved (fixed in 1.0.3-1) bullseye
debian
CVE-2007-6682P3MEDIUMCVSS 7.5PoCfixed in vlc 0.8.6.c-4.1 (bookworm)2007
CVE-2007-6682 [HIGH] CVE-2007-6682: vlc - Format string vulnerability in the httpd_FileCallBack function (network/httpd.c)... Format string vulnerability in the httpd_FileCallBack function (network/httpd.c) in VideoLAN VLC 0.8.6d allows remote attackers to execute arbitrary code via format string specifiers in the Connection parameter. Scope: local bookworm: resolved (fixed in 0.8.6.c-4.1) bullseye: resolved (fixed in 0.8.6.c-4.1) forky: resolved (fixed in 0.8.6.c-4.1) sid: resolved (fixed in 0.
debian
CVE-2013-1868P3CRITICALCVSS 9.3PoCfixed in vlc 2.0.5-1 (bookworm)2013
CVE-2013-1868 [CRITICAL] CVE-2013-1868: vlc - Multiple buffer overflows in VideoLAN VLC media player 2.0.4 and earlier allow r... Multiple buffer overflows in VideoLAN VLC media player 2.0.4 and earlier allow remote attackers to cause a denial of service (crash) and execute arbitrary code via vectors related to the (1) freetype renderer and (2) HTML subtitle parser. Scope: local bookworm: resolved (fixed in 2.0.5-1) bullseye: resolved (fixed in 2.0.5-1) forky: resolved (fixed in 2.0.5-1) sid: re
debian
CVE-2008-0984P3MEDIUMCVSS 9.3PoCfixed in vlc 0.8.6.e-1 (bookworm)2008
CVE-2008-0984 [CRITICAL] CVE-2008-0984: vlc - The MP4 demuxer (mp4.c) for VLC media player 0.8.6d and earlier, as used in Miro... The MP4 demuxer (mp4.c) for VLC media player 0.8.6d and earlier, as used in Miro Player 1.1 and earlier, allows remote attackers to overwrite arbitrary memory and execute arbitrary code via a malformed MP4 file. Scope: local bookworm: resolved (fixed in 0.8.6.e-1) bullseye: resolved (fixed in 0.8.6.e-1) forky: resolved (fixed in 0.8.6.e-1) sid: resolved (fixed in 0.8.
debian
CVE-2008-0296P3MEDIUMCVSS 10.0PoCfixed in vlc 0.8.6.c-6 (bookworm)2008
CVE-2008-0296 [CRITICAL] CVE-2008-0296: vlc - Heap-based buffer overflow in the libaccess_realrtsp plugin in VideoLAN VLC Medi... Heap-based buffer overflow in the libaccess_realrtsp plugin in VideoLAN VLC Media Player 0.8.6d and earlier on Windows might allow remote RTSP servers to cause a denial of service (application crash) or execute arbitrary code via a long string. Scope: local bookworm: resolved (fixed in 0.8.6.c-6) bullseye: resolved (fixed in 0.8.6.c-6) forky: resolved (fixed in 0.8.6.
debian
CVE-2008-3732P3CRITICALCVSS 9.3PoCfixed in vlc 0.8.6.h-2 (bookworm)2008
CVE-2008-3732 [CRITICAL] CVE-2008-3732: vlc - Integer overflow in the Open function in modules/demux/tta.c in VLC Media Player... Integer overflow in the Open function in modules/demux/tta.c in VLC Media Player 0.8.6i allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted TTA file, which triggers a heap-based buffer overflow. NOTE: some of these details are obtained from third party information. Scope: local bookworm: resolved (f
debian
CVE-2011-2194P3CRITICALCVSS 9.3PoCfixed in vlc 1.1.10-1 (bookworm)2011
CVE-2011-2194 [CRITICAL] CVE-2011-2194: vlc - Integer overflow in the XSPF playlist parser in VideoLAN VLC media player 0.8.5 ... Integer overflow in the XSPF playlist parser in VideoLAN VLC media player 0.8.5 through 1.1.9 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors that trigger a heap-based buffer overflow. Scope: local bookworm: resolved (fixed in 1.1.10-1) bullseye: resolved (fixed in 1.1.10-1) forky: resolved (fixe
debian
CVE-2008-4686P3MEDIUMCVSS 9.3PoCfixed in vlc 0.8.6.h-4.1 (bookworm)2008
CVE-2008-4686 [CRITICAL] CVE-2008-4686: vlc - Multiple integer overflows in ty.c in the TY demux plugin (aka the TiVo demuxer)... Multiple integer overflows in ty.c in the TY demux plugin (aka the TiVo demuxer) in VideoLAN VLC media player, probably 0.9.4, might allow remote attackers to execute arbitrary code via a crafted .ty file, a different vulnerability than CVE-2008-4654. Scope: local bookworm: resolved (fixed in 0.8.6.h-4.1) bullseye: resolved (fixed in 0.8.6.h-4.1) forky: resolved (fixe
debian
CVE-2008-0295P3MEDIUMCVSS 8.5PoCfixed in vlc 0.8.6.c-6 (bookworm)2008
CVE-2008-0295 [HIGH] CVE-2008-0295: vlc - Heap-based buffer overflow in modules/access/rtsp/real_sdpplin.c in the Xine lib... Heap-based buffer overflow in modules/access/rtsp/real_sdpplin.c in the Xine library, as used in VideoLAN VLC Media Player 0.8.6d and earlier, allows user-assisted remote attackers to cause a denial of service (crash) or execute arbitrary code via long Session Description Protocol (SDP) data. Scope: local bookworm: resolved (fixed in 0.8.6.c-6) bullseye: resolved (fixed i
debian
CVE-2008-5032P3MEDIUMCVSS 9.3PoCfixed in vlc 0.8.6.h-5 (bookworm)2008
CVE-2008-5032 [CRITICAL] CVE-2008-5032: vlc - Stack-based buffer overflow in VideoLAN VLC media player 0.5.0 through 0.9.5 mig... Stack-based buffer overflow in VideoLAN VLC media player 0.5.0 through 0.9.5 might allow user-assisted attackers to execute arbitrary code via the header of an invalid CUE image file, related to modules/access/vcd/cdrom.c. NOTE: this identifier originally included an issue related to RealText, but that issue has been assigned a separate identifier, CVE-2008-5036. Scop
debian
CVE-2007-6681P3LOWCVSS 7.5PoCfixed in vlc 0.8.6.c-4.1 (bookworm)2007
CVE-2007-6681 [HIGH] CVE-2007-6681: vlc - Stack-based buffer overflow in modules/demux/subtitle.c in VideoLAN VLC 0.8.6d a... Stack-based buffer overflow in modules/demux/subtitle.c in VideoLAN VLC 0.8.6d allows remote attackers to execute arbitrary code via a long subtitle in a (1) MicroDvd, (2) SSA, and (3) Vplayer file. Scope: local bookworm: resolved (fixed in 0.8.6.c-4.1) bullseye: resolved (fixed in 0.8.6.c-4.1) forky: resolved (fixed in 0.8.6.c-4.1) sid: resolved (fixed in 0.8.6.c-4.1) tr
debian
CVE-2013-6283P3LOWCVSS 7.5PoCfixed in vlc 2.1.0-2 (bookworm)2013
CVE-2013-6283 [HIGH] CVE-2013-6283: vlc - VideoLAN VLC Media Player 2.0.8 and earlier allows remote attackers to cause a d... VideoLAN VLC Media Player 2.0.8 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in a URL in a m3u file. Scope: local bookworm: resolved (fixed in 2.1.0-2) bullseye: resolved (fixed in 2.1.0-2) forky: resolved (fixed in 2.1.0-2) sid: resolved (fixed in 2.1.0-2) trixie: resolved (fixed in 2.1.0-2
debian
CVE-2017-8311P3HIGHCVSS 7.8PoCfixed in vlc 2.2.5-1 (bookworm)2017
CVE-2017-8311 [HIGH] CVE-2017-8311: vlc - Potential heap based buffer overflow in ParseJSS in VideoLAN VLC before 2.2.5 du... Potential heap based buffer overflow in ParseJSS in VideoLAN VLC before 2.2.5 due to skipping NULL terminator in an input string allows attackers to execute arbitrary code via a crafted subtitles file. Scope: local bookworm: resolved (fixed in 2.2.5-1) bullseye: resolved (fixed in 2.2.5-1) forky: resolved (fixed in 2.2.5-1) sid: resolved (fixed in 2.2.5-1) trixie: resolve
debian
Debian Vlc vulnerabilities | cvebase