Debian Vlc vulnerabilities
122 known vulnerabilities affecting debian/vlc.
Total CVEs
122
CISA KEV
0
Public exploits
33
Exploited in wild
0
Severity breakdown
CRITICAL14HIGH44MEDIUM41LOW23
Vulnerabilities
Page 5 of 7
CVE-2014-9630P4HIGHCVSS 7.8fixed in vlc 2.2.0~rc2-2 (bookworm)2014
CVE-2014-9630 [HIGH] CVE-2014-9630: vlc - The rtp_packetize_xiph_config function in modules/stream_out/rtpfmt.c in VideoLA...
The rtp_packetize_xiph_config function in modules/stream_out/rtpfmt.c in VideoLAN VLC media player before 2.1.6 uses a stack-allocation approach with a size determined by arbitrary input data, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted length value.
Scope: local
bookworm: resolved
debian
CVE-2019-14535P4HIGHCVSS 7.8fixed in vlc 3.0.8-1 (bookworm)2019
CVE-2019-14535 [HIGH] CVE-2019-14535: vlc - A divide-by-zero error exists in the SeekIndex function of demux/asf/asf.c in Vi...
A divide-by-zero error exists in the SeekIndex function of demux/asf/asf.c in VideoLAN VLC media player 3.0.7.1. As a result, an FPE can be triggered via a crafted WMV file.
Scope: local
bookworm: resolved (fixed in 3.0.8-1)
bullseye: resolved (fixed in 3.0.8-1)
forky: resolved (fixed in 3.0.8-1)
sid: resolved (fixed in 3.0.8-1)
trixie: resolved (fixed in 3.0.8-1)
debian
CVE-2020-26664P3LOWCVSS 7.8fixed in vlc 3.0.12-1 (bookworm)2020
CVE-2020-26664 [HIGH] CVE-2020-26664: vlc - A vulnerability in EbmlTypeDispatcher::send in VideoLAN VLC media player 3.0.11 ...
A vulnerability in EbmlTypeDispatcher::send in VideoLAN VLC media player 3.0.11 allows attackers to trigger a heap-based buffer overflow via a crafted .mkv file.
Scope: local
bookworm: resolved (fixed in 3.0.12-1)
bullseye: resolved (fixed in 3.0.12-1)
forky: resolved (fixed in 3.0.12-1)
sid: resolved (fixed in 3.0.12-1)
trixie: resolved (fixed in 3.0.12-1)
debian
CVE-2019-14777P4HIGHCVSS 7.8fixed in vlc 3.0.8-1 (bookworm)2019
CVE-2019-14777 [HIGH] CVE-2019-14777: vlc - The Control function of demux/mkv/mkv.cpp in VideoLAN VLC media player 3.0.7.1 h...
The Control function of demux/mkv/mkv.cpp in VideoLAN VLC media player 3.0.7.1 has a use-after-free.
Scope: local
bookworm: resolved (fixed in 3.0.8-1)
bullseye: resolved (fixed in 3.0.8-1)
forky: resolved (fixed in 3.0.8-1)
sid: resolved (fixed in 3.0.8-1)
trixie: resolved (fixed in 3.0.8-1)
debian
CVE-2019-19721P4HIGHCVSS 7.8fixed in vlc 3.0.9.2-1 (bookworm)2019
CVE-2019-19721 [HIGH] CVE-2019-19721: vlc - An off-by-one error in the DecodeBlock function in codec/sdl_image.c in VideoLAN...
An off-by-one error in the DecodeBlock function in codec/sdl_image.c in VideoLAN VLC media player before 3.0.9 allows remote attackers to cause a denial of service (memory corruption) via a crafted image file. NOTE: this may be related to the SDL_Image product.
Scope: local
bookworm: resolved (fixed in 3.0.9.2-1)
bullseye: resolved (fixed in 3.0.9.2-1)
forky: resolved (
debian
CVE-2022-41325P4HIGHCVSS 7.8fixed in vlc 3.0.18-1 (bookworm)2022
CVE-2022-41325 [HIGH] CVE-2022-41325: vlc - An integer overflow in the VNC module in VideoLAN VLC Media Player through 3.0.1...
An integer overflow in the VNC module in VideoLAN VLC Media Player through 3.0.17.4 allows attackers, by tricking a user into opening a crafted playlist or connecting to a rogue VNC server, to crash VLC or execute code under some conditions.
Scope: local
bookworm: resolved (fixed in 3.0.18-1)
bullseye: resolved (fixed in 3.0.18-0+deb11u1)
forky: resolved (fixed in 3.0.1
debian
CVE-2011-1684P4MEDIUMCVSS 6.8fixed in vlc 1.1.8-3 (bookworm)2011
CVE-2011-1684 [MEDIUM] CVE-2011-1684: vlc - Heap-based buffer overflow in the MP4_ReadBox_skcr function in libmp4.c in the M...
Heap-based buffer overflow in the MP4_ReadBox_skcr function in libmp4.c in the MP4 demultiplexer in VideoLAN VLC media player 1.x before 1.1.9 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted MP4 file.
Scope: local
bookworm: resolved (fixed in 1.1.8-3)
bullseye: resolved (fixed in 1.1.8-3)
forky: r
debian
CVE-2019-14778P4HIGHCVSS 7.8fixed in vlc 3.0.8-1 (bookworm)2019
CVE-2019-14778 [HIGH] CVE-2019-14778: vlc - The mkv::virtual_segment_c::seek method of demux/mkv/virtual_segment.cpp in Vide...
The mkv::virtual_segment_c::seek method of demux/mkv/virtual_segment.cpp in VideoLAN VLC media player 3.0.7.1 has a use-after-free.
Scope: local
bookworm: resolved (fixed in 3.0.8-1)
bullseye: resolved (fixed in 3.0.8-1)
forky: resolved (fixed in 3.0.8-1)
sid: resolved (fixed in 3.0.8-1)
trixie: resolved (fixed in 3.0.8-1)
debian
CVE-2021-25804P4HIGHCVSS 7.5fixed in vlc 3.0.12-1 (bookworm)2021
CVE-2021-25804 [HIGH] CVE-2021-25804: vlc - A NULL-pointer dereference in "Open" in avi.c of VideoLAN VLC Media Player 3.0.1...
A NULL-pointer dereference in "Open" in avi.c of VideoLAN VLC Media Player 3.0.11 can a denial of service (DOS) in the application.
Scope: local
bookworm: resolved (fixed in 3.0.12-1)
bullseye: resolved (fixed in 3.0.12-1)
forky: resolved (fixed in 3.0.12-1)
sid: resolved (fixed in 3.0.12-1)
trixie: resolved (fixed in 3.0.12-1)
debian
CVE-2013-3245P4LOWCVSS 6.3fixed in vlc 2.0.7-1 (bookworm)2013
CVE-2013-3245 [MEDIUM] CVE-2013-3245: vlc - plugins/demux/libmkv_plugin.dll in VideoLAN VLC Media Player 2.0.7, and possibly...
plugins/demux/libmkv_plugin.dll in VideoLAN VLC Media Player 2.0.7, and possibly other versions, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted MKV file, possibly involving an integer overflow and out-of-bounds read or heap-based buffer overflow, or an uncaught exception. NOTE: the vendor disputes the sever
debian
CVE-2017-9300P4HIGHCVSS 7.8fixed in vlc 2.2.6-3 (bookworm)2017
CVE-2017-9300 [HIGH] CVE-2017-9300: vlc - plugins\codec\libflac_plugin.dll in VideoLAN VLC media player 2.2.4 allows remot...
plugins\codec\libflac_plugin.dll in VideoLAN VLC media player 2.2.4 allows remote attackers to cause a denial of service (heap corruption and application crash) or possibly have unspecified other impact via a crafted FLAC file.
Scope: local
bookworm: resolved (fixed in 2.2.6-3)
bullseye: resolved (fixed in 2.2.6-3)
forky: resolved (fixed in 2.2.6-3)
sid: resolved (fixed i
debian
CVE-2012-3377P4MEDIUMCVSS 6.8fixed in vlc 2.0.2-1 (bookworm)2012
CVE-2012-3377 [MEDIUM] CVE-2012-3377: vlc - Heap-based buffer overflow in the Ogg_DecodePacket function in the OGG demuxer (...
Heap-based buffer overflow in the Ogg_DecodePacket function in the OGG demuxer (modules/demux/ogg.c) in VideoLAN VLC media player before 2.0.2 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted OGG file.
Scope: local
bookworm: resolved (fixed in 2.0.2-1)
bullseye: resolved (fixed in 2.0.2-1)
forky:
debian
CVE-2013-4388P4MEDIUMCVSS 6.8fixed in vlc 2.1.0-1 (bookworm)2013
CVE-2013-4388 [MEDIUM] CVE-2013-4388: vlc - Buffer overflow in the mp4a packetizer (modules/packetizer/mpeg4audio.c) in Vide...
Buffer overflow in the mp4a packetizer (modules/packetizer/mpeg4audio.c) in VideoLAN VLC Media Player before 2.0.8 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 2.1.0-1)
bullseye: resolved (fixed in 2.1.0-1)
forky: resolved (fixed in 2.1.0-1)
sid: resolv
debian
CVE-2011-2588P4MEDIUMCVSS 6.8fixed in vlc 1.1.11-1 (bookworm)2011
CVE-2011-2588 [MEDIUM] CVE-2011-2588: vlc - Heap-based buffer overflow in the AVI_ChunkRead_strf function in libavi.c in the...
Heap-based buffer overflow in the AVI_ChunkRead_strf function in libavi.c in the AVI demuxer in VideoLAN VLC media player before 1.1.11 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted AVI media file.
Scope: local
bookworm: resolved (fixed in 1.1.11-1)
bullseye: resolved (fixed in 1.1.11-1)
forky:
debian
CVE-2011-2587P4MEDIUMCVSS 6.8fixed in vlc 1.1.11-1 (bookworm)2011
CVE-2011-2587 [MEDIUM] CVE-2011-2587: vlc - Heap-based buffer overflow in the DemuxAudioSipr function in real.c in the RealM...
Heap-based buffer overflow in the DemuxAudioSipr function in real.c in the RealMedia demuxer in VideoLAN VLC media player 1.1.x before 1.1.11 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted Real Media file.
Scope: local
bookworm: resolved (fixed in 1.1.11-1)
bullseye: resolved (fixed in 1.1.11-1)
debian
CVE-2014-9626P4HIGHCVSS 7.8fixed in vlc 2.2.0~rc2-2 (bookworm)2014
CVE-2014-9626 [HIGH] CVE-2014-9626: vlc - Integer underflow in the MP4_ReadBox_String function in modules/demux/mp4/libmp4...
Integer underflow in the MP4_ReadBox_String function in modules/demux/mp4/libmp4.c in VideoLAN VLC media player before 2.1.6 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a box size less than 7.
Scope: local
bookworm: resolved (fixed in 2.2.0~rc2-2)
bullseye: resolved (fixed in 2.2.0~rc2-2)
forky: resolved (fixed in 2.2
debian
CVE-2014-9627P4HIGHCVSS 7.8fixed in vlc 2.2.0~rc2-2 (bookworm)2014
CVE-2014-9627 [HIGH] CVE-2014-9627: vlc - The MP4_ReadBox_String function in modules/demux/mp4/libmp4.c in VideoLAN VLC me...
The MP4_ReadBox_String function in modules/demux/mp4/libmp4.c in VideoLAN VLC media player before 2.1.6 performs an incorrect cast operation from a 64-bit integer to a 32-bit integer, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a large box size.
Scope: local
bookworm: resolved (fixed in 2.2.0~rc2-2)
bullseye: re
debian
CVE-2017-9301P4HIGHCVSS 7.8fixed in vlc 2.2.5.1-1 (bookworm)2017
CVE-2017-9301 [HIGH] CVE-2017-9301: vlc - plugins\audio_filter\libmpgatofixed32_plugin.dll in VideoLAN VLC media player 2....
plugins\audio_filter\libmpgatofixed32_plugin.dll in VideoLAN VLC media player 2.2.4 allows remote attackers to cause a denial of service (invalid read and application crash) or possibly have unspecified other impact via a crafted file.
Scope: local
bookworm: resolved (fixed in 2.2.5.1-1)
bullseye: resolved (fixed in 2.2.5.1-1)
forky: resolved (fixed in 2.2.5.1-1)
sid: res
debian
CVE-2019-5459P4HIGHCVSS 7.1fixed in vlc 3.0.7-1 (bookworm)2019
CVE-2019-5459 [HIGH] CVE-2019-5459: vlc - An Integer underflow in VLC Media Player versions < 3.0.7 leads to an out-of-ban...
An Integer underflow in VLC Media Player versions < 3.0.7 leads to an out-of-band read.
Scope: local
bookworm: resolved (fixed in 3.0.7-1)
bullseye: resolved (fixed in 3.0.7-1)
forky: resolved (fixed in 3.0.7-1)
sid: resolved (fixed in 3.0.7-1)
trixie: resolved (fixed in 3.0.7-1)
debian
CVE-2013-3564P4MEDIUMCVSS 5.3fixed in vlc 2.0.7-1 (bookworm)2013
CVE-2013-3564 [MEDIUM] CVE-2013-3564: vlc - The web interface in VideoLAN VLC media player before 2.0.7 has no access contro...
The web interface in VideoLAN VLC media player before 2.0.7 has no access control which allows remote attackers to view directory listings via the 'dir' command or issue other commands without authenticating.
Scope: local
bookworm: resolved (fixed in 2.0.7-1)
bullseye: resolved (fixed in 2.0.7-1)
forky: resolved (fixed in 2.0.7-1)
sid: resolved (fixed in 2.0.7-1)
trixie
debian