cbcvebase.

Debian Vlc vulnerabilities

122 known vulnerabilities affecting debian/vlc.

Total CVEs
122
CISA KEV
0
Public exploits
33
Exploited in wild
0
Severity breakdown
CRITICAL14HIGH44MEDIUM41LOW23

Vulnerabilities

Page 2 of 7
CVE-2008-3794P3MEDIUMCVSS 6.8PoCfixed in vlc 0.8.6.h-4 (bookworm)2008
CVE-2008-3794 [MEDIUM] CVE-2008-3794: vlc - Integer signedness error in the mms_ReceiveCommand function in modules/access/mm... Integer signedness error in the mms_ReceiveCommand function in modules/access/mms/mmstu.c in VLC Media Player 0.8.6i allows remote attackers to execute arbitrary code via a crafted mmst link with a negative size value, which bypasses a size check and triggers an integer overflow followed by a heap-based buffer overflow. Scope: local bookworm: resolved (fixed in 0.8.6.h-
debian
CVE-2008-1489P3MEDIUMCVSS 9.3PoCfixed in vlc 0.8.6.e-1.1 (bookworm)2008
CVE-2008-1489 [CRITICAL] CVE-2008-1489: vlc - Integer overflow in the MP4_ReadBox_rdrf function in libmp4.c for VLC 0.8.6e all... Integer overflow in the MP4_ReadBox_rdrf function in libmp4.c for VLC 0.8.6e allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted MP4 RDRF box that triggers a heap-based buffer overflow, a different vulnerability than CVE-2008-0984. Scope: local bookworm: resolved (fixed in 0.8.6.e-1.1) bullseye: resolved (fixe
debian
CVE-2008-0073P3MEDIUMCVSS 6.8PoCfixed in vlc 0.8.6.e-2 (bookworm)2008
CVE-2008-0073 [MEDIUM] CVE-2008-0073: vlc - Array index error in the sdpplin_parse function in input/libreal/sdpplin.c in xi... Array index error in the sdpplin_parse function in input/libreal/sdpplin.c in xine-lib 1.1.10.1 allows remote RTSP servers to execute arbitrary code via a large streamid SDP parameter. Scope: local bookworm: resolved (fixed in 0.8.6.e-2) bullseye: resolved (fixed in 0.8.6.e-2) forky: resolved (fixed in 0.8.6.e-2) sid: resolved (fixed in 0.8.6.e-2) trixie: resolved (fixe
debian
CVE-2008-1881P3MEDIUMCVSS 7.5PoCfixed in vlc 0.8.6.e-2.1 (bookworm)2008
CVE-2008-1881 [HIGH] CVE-2008-1881: vlc - Stack-based buffer overflow in the ParseSSA function (modules/demux/subtitle.c) ... Stack-based buffer overflow in the ParseSSA function (modules/demux/subtitle.c) in VLC 0.8.6e allows remote attackers to execute arbitrary code via a long subtitle in an SSA file. NOTE: this issue is due to an incomplete fix for CVE-2007-6681. Scope: local bookworm: resolved (fixed in 0.8.6.e-2.1) bullseye: resolved (fixed in 0.8.6.e-2.1) forky: resolved (fixed in 0.8.6.e
debian
CVE-2010-0364P3LOWCVSS 9.3PoCfixed in vlc 0.8.6.c-4.1 (bookworm)2010
CVE-2010-0364 [CRITICAL] CVE-2010-0364: vlc - Stack-based buffer overflow in VideoLAN VLC Media Player 0.8.6 allows user-assis... Stack-based buffer overflow in VideoLAN VLC Media Player 0.8.6 allows user-assisted remote attackers to execute arbitrary code via an ogg file with a crafted Advanced SubStation Alpha Subtitle (.ass) file, probably involving the Dialogue field. Scope: local bookworm: resolved (fixed in 0.8.6.c-4.1) bullseye: resolved (fixed in 0.8.6.c-4.1) forky: resolved (fixed in 0.
debian
CVE-2007-0017P3MEDIUMCVSS 6.8PoCfixed in vlc 0.8.6-svn20061012.debian-1.2 (bookworm)2007
CVE-2007-0017 [MEDIUM] CVE-2007-0017: vlc - Multiple format string vulnerabilities in (1) the cdio_log_handler function in m... Multiple format string vulnerabilities in (1) the cdio_log_handler function in modules/access/cdda/access.c in the CDDA (libcdda_plugin) plugin, and the (2) cdio_log_handler and (3) vcd_log_handler functions in modules/access/vcdx/access.c in the VCDX (libvcdx_plugin) plugin, in VideoLAN VLC 0.7.0 through 0.8.6 allow user-assisted remote attackers to execute arbitrary c
debian
CVE-2008-4558P3MEDIUMCVSS 6.8PoCfixed in vlc 0.9.3-1 (bookworm)2008
CVE-2008-4558 [MEDIUM] CVE-2008-4558: vlc - Array index error in VLC media player 0.9.2 allows remote attackers to overwrite... Array index error in VLC media player 0.9.2 allows remote attackers to overwrite arbitrary memory and execute arbitrary code via an XSPF playlist file with a negative identifier tag, which passes a signed comparison. Scope: local bookworm: resolved (fixed in 0.9.3-1) bullseye: resolved (fixed in 0.9.3-1) forky: resolved (fixed in 0.9.3-1) sid: resolved (fixed in 0.9.3-1
debian
CVE-2020-6072P3CRITICALCVSS 9.8fixed in libmicrodns 0.2.0-1 (forky)2020
CVE-2020-6072 [CRITICAL] CVE-2020-6072: libmicrodns - An exploitable code execution vulnerability exists in the label-parsing function... An exploitable code execution vulnerability exists in the label-parsing functionality of Videolabs libmicrodns 0.1.0. When parsing compressed labels in mDNS messages, the rr_decode function's return value is not checked, leading to a double free that could be exploited to execute arbitrary code. An attacker can send an mDNS message to trigger this vulnerabilit
debian
CVE-2007-0256P4LOWCVSS 7.8PoCfixed in vlc 0.8.6.c-1 (bookworm)2007
CVE-2007-0256 [HIGH] CVE-2007-0256: vlc - VideoLAN VLC 0.8.6a allows remote attackers to cause a denial of service (applic... VideoLAN VLC 0.8.6a allows remote attackers to cause a denial of service (application crash) via a crafted .wmv file. Scope: local bookworm: resolved (fixed in 0.8.6.c-1) bullseye: resolved (fixed in 0.8.6.c-1) forky: resolved (fixed in 0.8.6.c-1) sid: resolved (fixed in 0.8.6.c-1) trixie: resolved (fixed in 0.8.6.c-1)
debian
CVE-2014-6440P3LOWCVSS 9.8fixed in vlc 2.1.5-1 (bookworm)2014
CVE-2014-6440 [CRITICAL] CVE-2014-6440: vlc - VideoLAN VLC media player before 2.1.5 allows remote attackers to execute arbitr... VideoLAN VLC media player before 2.1.5 allows remote attackers to execute arbitrary code or cause a denial of service. Scope: local bookworm: resolved (fixed in 2.1.5-1) bullseye: resolved (fixed in 2.1.5-1) forky: resolved (fixed in 2.1.5-1) sid: resolved (fixed in 2.1.5-1) trixie: resolved (fixed in 2.1.5-1)
debian
CVE-2008-1769P4LOWCVSS 6.8PoCfixed in vlc 0.8.6.e-2.1 (bookworm)2008
CVE-2008-1769 [MEDIUM] CVE-2008-1769: vlc - VLC before 0.8.6f allow remote attackers to cause a denial of service (crash) vi... VLC before 0.8.6f allow remote attackers to cause a denial of service (crash) via a crafted Cinepak file that triggers an out-of-bounds array access and memory corruption. Scope: local bookworm: resolved (fixed in 0.8.6.e-2.1) bullseye: resolved (fixed in 0.8.6.e-2.1) forky: resolved (fixed in 0.8.6.e-2.1) sid: resolved (fixed in 0.8.6.e-2.1) trixie: resolved (fixed in
debian
CVE-2010-3276P3CRITICALCVSS 9.3fixed in vlc 1.1.8-1 (bookworm)2010
CVE-2010-3276 [CRITICAL] CVE-2010-3276: vlc - libdirectx_plugin.dll in VideoLAN VLC Media Player before 1.1.8 allows remote at... libdirectx_plugin.dll in VideoLAN VLC Media Player before 1.1.8 allows remote attackers to execute arbitrary code via a crafted width in an NSV file. Scope: local bookworm: resolved (fixed in 1.1.8-1) bullseye: resolved (fixed in 1.1.8-1) forky: resolved (fixed in 1.1.8-1) sid: resolved (fixed in 1.1.8-1) trixie: resolved (fixed in 1.1.8-1)
debian
CVE-2013-6933P3LOWCVSS 7.5fixed in mplayer 2:1.1.1+svn37434-1 (bookworm)2013
CVE-2013-6933 [HIGH] CVE-2013-6933: mplayer - The parseRTSPRequestString function in Live Networks Live555 Streaming Media 201... The parseRTSPRequestString function in Live Networks Live555 Streaming Media 2011.08.13 through 2013.11.25, as used in VideoLAN VLC Media Player, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a (1) space or (2) tab character at the beginning of an RTSP message, which triggers an integer underflow, infinite loop, a
debian
CVE-2007-3316P3MEDIUMCVSS 9.3fixed in vlc 0.8.6.c-1 (bookworm)2007
CVE-2007-3316 [CRITICAL] CVE-2007-3316: vlc - Multiple format string vulnerabilities in plugins in VideoLAN VLC Media Player b... Multiple format string vulnerabilities in plugins in VideoLAN VLC Media Player before 0.8.6c allow remote attackers to cause a denial of service (crash) or execute arbitrary code via format string specifiers in (1) an Ogg/Vorbis file, (2) an Ogg/Theora file, (3) a CDDB entry for a CD Digital Audio (CDDA) file, or (4) Service Announce Protocol (SAP) multicast packets.
debian
CVE-2009-1045P4LOWCVSS 5.0PoCfixed in vlc 0.9.9a-1 (bookworm)2009
CVE-2009-1045 [MEDIUM] CVE-2009-1045: vlc - requests/status.xml in VLC 0.9.8a allows remote attackers to cause a denial of s... requests/status.xml in VLC 0.9.8a allows remote attackers to cause a denial of service (stack consumption and crash) via a long input argument in an in_play action. Scope: local bookworm: resolved (fixed in 0.9.9a-1) bullseye: resolved (fixed in 0.9.9a-1) forky: resolved (fixed in 0.9.9a-1) sid: resolved (fixed in 0.9.9a-1) trixie: resolved (fixed in 0.9.9a-1)
debian
CVE-2023-47359P3CRITICALCVSS 9.8fixed in vlc 3.0.20-0+deb12u1 (bookworm)2023
CVE-2023-47359 [CRITICAL] CVE-2023-47359: vlc - Videolan VLC prior to version 3.0.20 contains an incorrect offset read that lead... Videolan VLC prior to version 3.0.20 contains an incorrect offset read that leads to a Heap-Based Buffer Overflow in function GetPacket() and results in a memory corruption. Scope: local bookworm: resolved (fixed in 3.0.20-0+deb12u1) bullseye: resolved (fixed in 3.0.20-0+deb11u1) forky: resolved (fixed in 3.0.20-1) sid: resolved (fixed in 3.0.20-1) trixie: resolved
debian
CVE-2019-13962P3LOWCVSS 9.8fixed in vlc 3.0.8-1 (bookworm)2019
CVE-2019-13962 [CRITICAL] CVE-2019-13962: vlc - lavc_CopyPicture in modules/codec/avcodec/video.c in VideoLAN VLC media player t... lavc_CopyPicture in modules/codec/avcodec/video.c in VideoLAN VLC media player through 3.0.7 has a heap-based buffer over-read because it does not properly validate the width and height. Scope: local bookworm: resolved (fixed in 3.0.8-1) bullseye: resolved (fixed in 3.0.8-1) forky: resolved (fixed in 3.0.8-1) sid: resolved (fixed in 3.0.8-1) trixie: resolved (fixed
debian
CVE-2008-5276P3LOWCVSS 9.3fixed in vlc 0.9.8a-1 (bookworm)2008
CVE-2008-5276 [CRITICAL] CVE-2008-5276: vlc - Integer overflow in the ReadRealIndex function in real.c in the Real demuxer plu... Integer overflow in the ReadRealIndex function in real.c in the Real demuxer plugin in VideoLAN VLC media player 0.9.0 through 0.9.7 allows remote attackers to execute arbitrary code via a malformed RealMedia (.rm) file that triggers a heap-based buffer overflow. Scope: local bookworm: resolved (fixed in 0.9.8a-1) bullseye: resolved (fixed in 0.9.8a-1) forky: resolved
debian
CVE-2008-2430P3MEDIUMCVSS 9.3fixed in vlc 0.8.6.h-1 (bookworm)2008
CVE-2008-2430 [CRITICAL] CVE-2008-2430: vlc - Integer overflow in the Open function in modules/demux/wav.c in VLC Media Player... Integer overflow in the Open function in modules/demux/wav.c in VLC Media Player 0.8.6h on Windows allows remote attackers to execute arbitrary code via a large fmt chunk in a WAV file. Scope: local bookworm: resolved (fixed in 0.8.6.h-1) bullseye: resolved (fixed in 0.8.6.h-1) forky: resolved (fixed in 0.8.6.h-1) sid: resolved (fixed in 0.8.6.h-1) trixie: resolved (f
debian
CVE-2010-2062P3MEDIUMCVSS 7.5fixed in mplayer 2:1.0~rc3+svn20100502-3 (bookworm)2010
CVE-2010-2062 [HIGH] CVE-2010-2062: mplayer - Integer underflow in the real_get_rdt_chunk function in real.c, as used in modul... Integer underflow in the real_get_rdt_chunk function in real.c, as used in modules/access/rtsp/real.c in VideoLAN VLC media player before 1.0.1 and stream/realrtsp/real.c in MPlayer before r29447, allows remote attackers to execute arbitrary code via a crafted length value in an RDT chunk header. Scope: local bookworm: resolved (fixed in 2:1.0~rc3+svn20100502-3) bulls
debian
Debian Vlc vulnerabilities | cvebase