cbcvebase.

Debian Vlc vulnerabilities

122 known vulnerabilities affecting debian/vlc.

Total CVEs
122
CISA KEV
0
Public exploits
33
Exploited in wild
0
Severity breakdown
CRITICAL14HIGH44MEDIUM41LOW23

Vulnerabilities

Page 3 of 7
CVE-2017-10699P3CRITICALCVSS 9.8fixed in vlc 2.2.6-3 (bookworm)2017
CVE-2017-10699 [CRITICAL] CVE-2017-10699: vlc - avcodec 2.2.x, as used in VideoLAN VLC media player 2.2.7-x before 2017-06-29, a... avcodec 2.2.x, as used in VideoLAN VLC media player 2.2.7-x before 2017-06-29, allows out-of-bounds heap memory write due to calling memcpy() with a wrong size, leading to a denial of service (application crash) or possibly code execution. Scope: local bookworm: resolved (fixed in 2.2.6-3) bullseye: resolved (fixed in 2.2.6-3) forky: resolved (fixed in 2.2.6-3) sid:
debian
CVE-2014-1684P4LOWCVSS 4.3PoCfixed in vlc 2.1.4-1 (bookworm)2014
CVE-2014-1684 [MEDIUM] CVE-2014-1684: vlc - The ASF_ReadObject_file_properties function in modules/demux/asf/libasf.c in the... The ASF_ReadObject_file_properties function in modules/demux/asf/libasf.c in the ASF Demuxer in VideoLAN VLC Media Player before 2.1.3 allows remote attackers to cause a denial of service (divide-by-zero error and crash) via a zero minimum and maximum data packet size in an ASF file. Scope: local bookworm: resolved (fixed in 2.1.4-1) bullseye: resolved (fixed in 2.1.4-1
debian
CVE-2011-3623P3HIGHCVSS 7.5fixed in vlc 1.1.3-1 (bookworm)2011
CVE-2011-3623 [HIGH] CVE-2011-3623: vlc - Multiple stack-based buffer overflows in VideoLAN VLC media player before 1.0.2 ... Multiple stack-based buffer overflows in VideoLAN VLC media player before 1.0.2 allow remote attackers to execute arbitrary code via (1) a crafted ASF file, related to the ASF_ObjectDumpDebug function in modules/demux/asf/libasf.c; (2) a crafted AVI file, related to the AVI_ChunkDumpDebug_level function in modules/demux/avi/libavi.c; or (3) a crafted MP4 file, related to
debian
CVE-2012-1776P3LOWCVSS 9.3fixed in vlc 2.0.1-1 (bookworm)2012
CVE-2012-1776 [CRITICAL] CVE-2012-1776: vlc - Multiple heap-based buffer overflows in VideoLAN VLC media player before 2.0.1 a... Multiple heap-based buffer overflows in VideoLAN VLC media player before 2.0.1 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted Real RTSP stream. Scope: local bookworm: resolved (fixed in 2.0.1-1) bullseye: resolved (fixed in 2.0.1-1) forky: resolved (fixed in 2.0.1-1) sid: resolved (fixed in 2.0.
debian
CVE-2019-12874P3CRITICALCVSS 9.8fixed in vlc 3.0.7-1 (bookworm)2019
CVE-2019-12874 [CRITICAL] CVE-2019-12874: vlc - An issue was discovered in zlib_decompress_extra in modules/demux/mkv/util.cpp i... An issue was discovered in zlib_decompress_extra in modules/demux/mkv/util.cpp in VideoLAN VLC media player 3.x through 3.0.7. The Matroska demuxer, while parsing a malformed MKV file type, has a double free. Scope: local bookworm: resolved (fixed in 3.0.7-1) bullseye: resolved (fixed in 3.0.7-1) forky: resolved (fixed in 3.0.7-1) sid: resolved (fixed in 3.0.7-1) tr
debian
CVE-2018-19857P3CRITICALCVSS 9.1fixed in vlc 3.0.4-4 (bookworm)2018
CVE-2018-19857 [CRITICAL] CVE-2018-19857: vlc - The CAF demuxer in modules/demux/caf.c in VideoLAN VLC media player 3.0.4 may re... The CAF demuxer in modules/demux/caf.c in VideoLAN VLC media player 3.0.4 may read memory from an uninitialized pointer when processing magic cookies in CAF files, because a ReadKukiChunk() cast converts a return value to an unsigned int even if that value is negative. This could result in a denial of service and/or a potential infoleak. Scope: local bookworm: resol
debian
CVE-2011-0021P3CRITICALCVSS 9.3fixed in vlc 1.1.3-1squeeze2 (bookworm)2011
CVE-2011-0021 [CRITICAL] CVE-2011-0021: vlc - Multiple heap-based buffer overflows in cdg.c in the CDG decoder in VideoLAN VLC... Multiple heap-based buffer overflows in cdg.c in the CDG decoder in VideoLAN VLC Media Player before 1.1.6 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted CDG video. Scope: local bookworm: resolved (fixed in 1.1.3-1squeeze2) bullseye: resolved (fixed in 1.1.3-1squeeze2) forky: resolved (fixed in
debian
CVE-2012-0023P3CRITICALCVSS 9.3fixed in vlc 1.1.13-1 (bookworm)2012
CVE-2012-0023 [CRITICAL] CVE-2012-0023: vlc - Double free vulnerability in the get_chunk_header function in modules/demux/ty.c... Double free vulnerability in the get_chunk_header function in modules/demux/ty.c in VideoLAN VLC media player 0.9.0 through 1.1.12 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TiVo (TY) file. Scope: local bookworm: resolved (fixed in 1.1.13-1) bullseye: resolved (fixed in 1.1.13-1) forky: resolved (fixe
debian
CVE-2015-5949P3MEDIUMCVSS 6.8fixed in vlc 2.2.1-3 (bookworm)2015
CVE-2015-5949 [MEDIUM] CVE-2015-5949: vlc - VideoLAN VLC media player 2.2.1 allows remote attackers to cause a denial of ser... VideoLAN VLC media player 2.2.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted 3GP file, which triggers the freeing of arbitrary pointers. Scope: local bookworm: resolved (fixed in 2.2.1-3) bullseye: resolved (fixed in 2.2.1-3) forky: resolved (fixed in 2.2.1-3) sid: resolved (fixed in 2.2.1-3) trixie: reso
debian
CVE-2005-4048P3MEDIUMCVSS 7.5fixed in ffmpeg 0.cvs20050918-5.1 (bookworm)2005
CVE-2005-4048 [HIGH] CVE-2005-4048: ffmpeg - Heap-based buffer overflow in the avcodec_default_get_buffer function (utils.c) ... Heap-based buffer overflow in the avcodec_default_get_buffer function (utils.c) in FFmpeg libavcodec 0.4.9-pre1 and earlier, as used in products such as (1) mplayer, (2) xine-lib, (3) Xmovie, and (4) GStreamer, allows remote attackers to execute arbitrary commands via small PNG images with palettes. Scope: local bookworm: resolved (fixed in 0.cvs20050918-5.1) bullseye:
debian
CVE-2010-3907P3CRITICALCVSS 9.3fixed in vlc 1.1.3-1squeeze1 (bookworm)2010
CVE-2010-3907 [CRITICAL] CVE-2010-3907: vlc - Multiple integer overflows in real.c in the Real demuxer plugin in VideoLAN VLC ... Multiple integer overflows in real.c in the Real demuxer plugin in VideoLAN VLC Media Player before 1.1.6 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a zero i_subpackets value in a Real Media file, leading to a heap-based buffer overflow. Scope: local bookworm: resolved (fixed in 1.1.3-1squeeze1) bulls
debian
CVE-2012-5470P4MEDIUMCVSS 4.3PoCfixed in vlc 2.0.4-1 (bookworm)2012
CVE-2012-5470 [MEDIUM] CVE-2012-5470: vlc - libpng_plugin in VideoLAN VLC media player 2.0.3 allows remote attackers to caus... libpng_plugin in VideoLAN VLC media player 2.0.3 allows remote attackers to cause a denial of service (application crash) via a crafted PNG file. Scope: local bookworm: resolved (fixed in 2.0.4-1) bullseye: resolved (fixed in 2.0.4-1) forky: resolved (fixed in 2.0.4-1) sid: resolved (fixed in 2.0.4-1) trixie: resolved (fixed in 2.0.4-1)
debian
CVE-2024-46461P3HIGHCVSS 8.0fixed in vlc 3.0.21-0+deb12u1 (bookworm)2024
CVE-2024-46461 [HIGH] CVE-2024-46461: vlc - VLC media player 3.0.20 and earlier is vulnerable to denial of service through a... VLC media player 3.0.20 and earlier is vulnerable to denial of service through an integer overflow which could be triggered with a maliciously crafted mms stream (heap based overflow). If successful, a malicious third party could trigger either a crash of VLC or an arbitrary code execution with the target user's privileges. Scope: local bookworm: resolved (fixed in 3.0.
debian
CVE-2023-47360P3HIGHCVSS 7.5fixed in vlc 3.0.20-0+deb12u1 (bookworm)2023
CVE-2023-47360 [HIGH] CVE-2023-47360: vlc - Videolan VLC prior to version 3.0.20 contains an Integer underflow that leads to... Videolan VLC prior to version 3.0.20 contains an Integer underflow that leads to an incorrect packet length. Scope: local bookworm: resolved (fixed in 3.0.20-0+deb12u1) bullseye: resolved (fixed in 3.0.20-0+deb11u1) forky: resolved (fixed in 3.0.20-1) sid: resolved (fixed in 3.0.20-1) trixie: resolved (fixed in 3.0.20-1)
debian
CVE-2017-17670P3HIGHCVSS 8.8fixed in vlc 3.0.0~rc2-1 (bookworm)2017
CVE-2017-17670 [HIGH] CVE-2017-17670: vlc - In VideoLAN VLC media player through 2.2.8, there is a type conversion vulnerabi... In VideoLAN VLC media player through 2.2.8, there is a type conversion vulnerability in modules/demux/mp4/libmp4.c in the MP4 demux module leading to a invalid free, because the type of a box may be changed between a read operation and a free operation. Scope: local bookworm: resolved (fixed in 3.0.0~rc2-1) bullseye: resolved (fixed in 3.0.0~rc2-1) forky: resolved (fixe
debian
CVE-2012-2396P4LOWCVSS 4.3PoCfixed in taglib 1.7.2-1 (bookworm)2012
CVE-2012-2396 [MEDIUM] CVE-2012-2396: taglib - VideoLAN VLC media player 2.0.1 allows remote attackers to cause a denial of ser... VideoLAN VLC media player 2.0.1 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted MP4 file. Scope: local bookworm: resolved (fixed in 1.7.2-1) bullseye: resolved (fixed in 1.7.2-1) forky: resolved (fixed in 1.7.2-1) sid: resolved (fixed in 1.7.2-1) trixie: resolved (fixed in 1.7.2-1)
debian
CVE-2014-9629P3HIGHCVSS 7.8fixed in vlc 2.2.0~rc2-2 (bookworm)2014
CVE-2014-9629 [HIGH] CVE-2014-9629: vlc - Integer overflow in the Encode function in modules/codec/schroedinger.c in Video... Integer overflow in the Encode function in modules/codec/schroedinger.c in VideoLAN VLC media player before 2.1.6 and 2.2.x before 2.2.1 allows remote attackers to conduct buffer overflow attacks and execute arbitrary code via a crafted length value. Scope: local bookworm: resolved (fixed in 2.2.0~rc2-2) bullseye: resolved (fixed in 2.2.0~rc2-2) forky: resolved (fixed in
debian
CVE-2020-6079P3HIGHCVSS 7.5fixed in libmicrodns 0.2.0-1 (forky)2020
CVE-2020-6079 [HIGH] CVE-2020-6079: libmicrodns - An exploitable denial-of-service vulnerability exists in the resource allocation... An exploitable denial-of-service vulnerability exists in the resource allocation handling of Videolabs libmicrodns 0.1.0. When encountering errors while parsing mDNS messages, some allocated data is not freed, possibly leading to a denial-of-service condition via resource exhaustion. An attacker can send one mDNS message repeatedly to trigger this vulnerability th
debian
CVE-2020-6077P3HIGHCVSS 7.5fixed in libmicrodns 0.2.0-1 (forky)2020
CVE-2020-6077 [HIGH] CVE-2020-6077: libmicrodns - An exploitable denial-of-service vulnerability exists in the message-parsing fun... An exploitable denial-of-service vulnerability exists in the message-parsing functionality of Videolabs libmicrodns 0.1.0. When parsing mDNS messages, the implementation does not properly keep track of the available data in the message, possibly leading to an out-of-bounds read that would result in a denial of service. An attacker can send an mDNS message to trigg
debian
CVE-2020-6080P3HIGHCVSS 7.5fixed in libmicrodns 0.2.0-1 (forky)2020
CVE-2020-6080 [HIGH] CVE-2020-6080: libmicrodns - An exploitable denial-of-service vulnerability exists in the resource allocation... An exploitable denial-of-service vulnerability exists in the resource allocation handling of Videolabs libmicrodns 0.1.0. When encountering errors while parsing mDNS messages, some allocated data is not freed, possibly leading to a denial-of-service condition via resource exhaustion. An attacker can send one mDNS message repeatedly to trigger this vulnerability th
debian
Debian Vlc vulnerabilities | cvebase