cbcvebase.

Debian Vlc vulnerabilities

122 known vulnerabilities affecting debian/vlc.

Total CVEs
122
CISA KEV
0
Public exploits
33
Exploited in wild
0
Severity breakdown
CRITICAL14HIGH44MEDIUM41LOW23

Vulnerabilities

Page 6 of 7
CVE-2021-25801P4HIGHCVSS 7.1fixed in vlc 3.0.12-1 (bookworm)2021
CVE-2021-25801 [HIGH] CVE-2021-25801: vlc - A buffer overflow vulnerability in the __Parse_indx component of VideoLAN VLC Me... A buffer overflow vulnerability in the __Parse_indx component of VideoLAN VLC Media Player 3.0.11 allows attackers to cause an out-of-bounds read via a crafted .avi file. Scope: local bookworm: resolved (fixed in 3.0.12-1) bullseye: resolved (fixed in 3.0.12-1) forky: resolved (fixed in 3.0.12-1) sid: resolved (fixed in 3.0.12-1) trixie: resolved (fixed in 3.0.12-1)
debian
CVE-2007-6683P4MEDIUMCVSS 5.0fixed in vlc 0.8.6.c-4.1 (bookworm)2007
CVE-2007-6683 [MEDIUM] CVE-2007-6683: vlc - The browser plugin in VideoLAN VLC 0.8.6d allows remote attackers to overwrite a... The browser plugin in VideoLAN VLC 0.8.6d allows remote attackers to overwrite arbitrary files via (1) the :demuxdump-file option in a filename in a playlist, or (2) a EXTVLCOPT statement in an MP3 file, possibly an argument injection vulnerability. Scope: local bookworm: resolved (fixed in 0.8.6.c-4.1) bullseye: resolved (fixed in 0.8.6.c-4.1) forky: resolved (fixed in
debian
CVE-2021-25802P4HIGHCVSS 7.1fixed in vlc 3.0.12-1 (bookworm)2021
CVE-2021-25802 [HIGH] CVE-2021-25802: vlc - A buffer overflow vulnerability in the AVI_ExtractSubtitle component of VideoLAN... A buffer overflow vulnerability in the AVI_ExtractSubtitle component of VideoLAN VLC Media Player 3.0.11 allows attackers to cause an out-of-bounds read via a crafted .avi file. Scope: local bookworm: resolved (fixed in 3.0.12-1) bullseye: resolved (fixed in 3.0.12-1) forky: resolved (fixed in 3.0.12-1) sid: resolved (fixed in 3.0.12-1) trixie: resolved (fixed in 3.0.12
debian
CVE-2021-25803P4HIGHCVSS 7.1fixed in vlc 3.0.12-1 (bookworm)2021
CVE-2021-25803 [HIGH] CVE-2021-25803: vlc - A buffer overflow vulnerability in the vlc_input_attachment_New component of Vid... A buffer overflow vulnerability in the vlc_input_attachment_New component of VideoLAN VLC Media Player 3.0.11 allows attackers to cause an out-of-bounds read via a crafted .avi file. Scope: local bookworm: resolved (fixed in 3.0.12-1) bullseye: resolved (fixed in 3.0.12-1) forky: resolved (fixed in 3.0.12-1) sid: resolved (fixed in 3.0.12-1) trixie: resolved (fixed in 3
debian
CVE-2013-3565P4LOWCVSS 6.1fixed in vlc 2.0.7-1 (bookworm)2013
CVE-2013-3565 [MEDIUM] CVE-2013-3565: vlc - Multiple cross-site scripting (XSS) vulnerabilities in the HTTP Interface in Vid... Multiple cross-site scripting (XSS) vulnerabilities in the HTTP Interface in VideoLAN VLC Media Player before 2.0.7 allow remote attackers to inject arbitrary web script or HTML via the (1) command parameter to requests/vlm_cmd.xml, (2) dir parameter to requests/browse.xml, or (3) URI in a request, which is returned in an error message through share/lua/intf/http.lua. S
debian
CVE-2007-3467P4HIGHCVSS 7.8fixed in vlc 0.8.6.c-1 (bookworm)2007
CVE-2007-3467 [HIGH] CVE-2007-3467: vlc - Integer overflow in the __status_Update function in stats.c VideoLAN VLC Media P... Integer overflow in the __status_Update function in stats.c VideoLAN VLC Media Player before 0.8.6c allows remote attackers to cause a denial of service (crash) via a WAV file with a large sample rate. Scope: local bookworm: resolved (fixed in 0.8.6.c-1) bullseye: resolved (fixed in 0.8.6.c-1) forky: resolved (fixed in 0.8.6.c-1) sid: resolved (fixed in 0.8.6.c-1) trixie:
debian
CVE-2007-3468P4HIGHCVSS 7.8fixed in vlc 0.8.6.c.debian-1 (bookworm)2007
CVE-2007-3468 [HIGH] CVE-2007-3468: vlc - input.c in VideoLAN VLC Media Player before 0.8.6c allows remote attackers to ca... input.c in VideoLAN VLC Media Player before 0.8.6c allows remote attackers to cause a denial of service (crash) via a crafted WAV file that causes an uninitialized i_nb_resamplers variable to be used. Scope: local bookworm: resolved (fixed in 0.8.6.c.debian-1) bullseye: resolved (fixed in 0.8.6.c.debian-1) forky: resolved (fixed in 0.8.6.c.debian-1) sid: resolved (fixed i
debian
CVE-2008-1768P4MEDIUMCVSS 6.8fixed in vlc 0.8.6.e-2.1 (bookworm)2008
CVE-2008-1768 [MEDIUM] CVE-2008-1768: vlc - Multiple integer overflows in VLC before 0.8.6f allow remote attackers to cause ... Multiple integer overflows in VLC before 0.8.6f allow remote attackers to cause a denial of service (crash) via the (1) MP4 demuxer, (2) Real demuxer, and (3) Cinepak codec, which triggers a buffer overflow. Scope: local bookworm: resolved (fixed in 0.8.6.e-2.1) bullseye: resolved (fixed in 0.8.6.e-2.1) forky: resolved (fixed in 0.8.6.e-2.1) sid: resolved (fixed in 0.8.
debian
CVE-2004-1476P4MEDIUMCVSS 5.1fixed in libcdio 0.69 (bookworm)2004
CVE-2004-1476 [MEDIUM] CVE-2004-1476: libcdio - Stack-based buffer overflow in the VideoCD (VCD) code in xine-lib 1-rc2 through ... Stack-based buffer overflow in the VideoCD (VCD) code in xine-lib 1-rc2 through 1-rc5, as derived from libcdio, allows attackers to execute arbitrary code via a VideoCD with an unterminated disk label. Scope: local bookworm: resolved (fixed in 0.69) bullseye: resolved (fixed in 0.69) forky: resolved (fixed in 0.69) sid: resolved (fixed in 0.69) trixie: resolved (fix
debian
CVE-2025-51602P4MEDIUMCVSS 4.8fixed in vlc 3.0.22-0+deb12u1 (bookworm)2025
CVE-2025-51602 [MEDIUM] CVE-2025-51602: vlc - mmstu.c in VideoLAN VLC media player before 3.0.22 allows an out-of-bounds read ... mmstu.c in VideoLAN VLC media player before 3.0.22 allows an out-of-bounds read and denial of service via a crafted 0x01 response from an MMS server. Scope: local bookworm: resolved (fixed in 3.0.22-0+deb12u1) bullseye: resolved (fixed in 3.0.23-0+deb11u1) forky: resolved (fixed in 3.0.22-1) sid: resolved (fixed in 3.0.22-1) trixie: resolved (fixed in 3.0.22-0+deb13u1
debian
CVE-2017-8312P4MEDIUMCVSS 5.5fixed in vlc 2.2.6-1~deb9u1 (bookworm)2017
CVE-2017-8312 [MEDIUM] CVE-2017-8312: vlc - Heap out-of-bound read in ParseJSS in VideoLAN VLC due to missing check of strin... Heap out-of-bound read in ParseJSS in VideoLAN VLC due to missing check of string length allows attackers to read heap uninitialized data via a crafted subtitles file. Scope: local bookworm: resolved (fixed in 2.2.6-1~deb9u1) bullseye: resolved (fixed in 2.2.6-1~deb9u1) forky: resolved (fixed in 2.2.6-1~deb9u1) sid: resolved (fixed in 2.2.6-1~deb9u1) trixie: resolved (f
debian
CVE-2019-5460P4MEDIUMCVSS 5.5fixed in vlc 3.0.7-1 (bookworm)2019
CVE-2019-5460 [MEDIUM] CVE-2019-5460: vlc - Double Free in VLC versions <= 3.0.6 leads to a crash. Double Free in VLC versions <= 3.0.6 leads to a crash. Scope: local bookworm: resolved (fixed in 3.0.7-1) bullseye: resolved (fixed in 3.0.7-1) forky: resolved (fixed in 3.0.7-1) sid: resolved (fixed in 3.0.7-1) trixie: resolved (fixed in 3.0.7-1)
debian
CVE-2016-3941P4MEDIUMCVSS 5.5fixed in vlc 2.2.0-1 (bookworm)2016
CVE-2016-3941 [MEDIUM] CVE-2016-3941: vlc - Buffer overflow in the AStreamPeekStream function in input/stream.c in VideoLAN ... Buffer overflow in the AStreamPeekStream function in input/stream.c in VideoLAN VLC media player before 2.2.0 allows remote attackers to cause a denial of service (crash) via a crafted wav file, related to "seek across EOF." Scope: local bookworm: resolved (fixed in 2.2.0-1) bullseye: resolved (fixed in 2.2.0-1) forky: resolved (fixed in 2.2.0-1) sid: resolved (fixed in
debian
CVE-2010-1443P4LOWCVSS 5.0fixed in vlc 1.0.6-1 (bookworm)2010
CVE-2010-1443 [MEDIUM] CVE-2010-1443: vlc - The parse_track_node function in modules/demux/playlist/xspf.c in the XSPF playl... The parse_track_node function in modules/demux/playlist/xspf.c in the XSPF playlist parser in VideoLAN VLC media player before 1.0.6 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an empty location element in an XML Shareable Playlist Format (XSPF) document. Scope: local bookworm: resolved (fixed in 1.0.6-1) bul
debian
CVE-2014-9743P4MEDIUMCVSS 4.3fixed in vlc 2.2.0~rc2-1 (bookworm)2014
CVE-2014-9743 [MEDIUM] CVE-2014-9743: vlc - Cross-site scripting (XSS) vulnerability in the httpd_HtmlError function in netw... Cross-site scripting (XSS) vulnerability in the httpd_HtmlError function in network/httpd.c in the web interface in VideoLAN VLC Media Player before 2.2.0 allows remote attackers to inject arbitrary web script or HTML via the path info. Scope: local bookworm: resolved (fixed in 2.2.0~rc2-1) bullseye: resolved (fixed in 2.2.0~rc2-1) forky: resolved (fixed in 2.2.0~rc2-1)
debian
CVE-2019-14534P4MEDIUMCVSS 5.5fixed in vlc 3.0.8-1 (bookworm)2019
CVE-2019-14534 [MEDIUM] CVE-2019-14534: vlc - In VideoLAN VLC media player 3.0.7.1, there is a NULL pointer dereference at the... In VideoLAN VLC media player 3.0.7.1, there is a NULL pointer dereference at the function SeekPercent of demux/asf/asf.c that will lead to a denial of service attack. Scope: local bookworm: resolved (fixed in 3.0.8-1) bullseye: resolved (fixed in 3.0.8-1) forky: resolved (fixed in 3.0.8-1) sid: resolved (fixed in 3.0.8-1) trixie: resolved (fixed in 3.0.8-1)
debian
CVE-2007-6684P4MEDIUMCVSS 5.0fixed in vlc 0.8.6.c-4.1 (bookworm)2007
CVE-2007-6684 [MEDIUM] CVE-2007-6684: vlc - The RTSP module in VideoLAN VLC 0.8.6d allows remote attackers to cause a denial... The RTSP module in VideoLAN VLC 0.8.6d allows remote attackers to cause a denial of service (crash) via a request without a Transport parameter, which triggers a NULL pointer dereference. Scope: local bookworm: resolved (fixed in 0.8.6.c-4.1) bullseye: resolved (fixed in 0.8.6.c-4.1) forky: resolved (fixed in 0.8.6.c-4.1) sid: resolved (fixed in 0.8.6.c-4.1) trixie: res
debian
CVE-2017-8313P4MEDIUMCVSS 5.5fixed in vlc 2.2.5-1 (bookworm)2017
CVE-2017-8313 [MEDIUM] CVE-2017-8313: vlc - Heap out-of-bound read in ParseJSS in VideoLAN VLC before 2.2.5 due to missing c... Heap out-of-bound read in ParseJSS in VideoLAN VLC before 2.2.5 due to missing check of string termination allows attackers to read data beyond allocated memory and potentially crash the process via a crafted subtitles file. Scope: local bookworm: resolved (fixed in 2.2.5-1) bullseye: resolved (fixed in 2.2.5-1) forky: resolved (fixed in 2.2.5-1) sid: resolved (fixed in
debian
CVE-2010-2937P4MEDIUMCVSS 5.0fixed in vlc 1.1.3-1 (bookworm)2010
CVE-2010-2937 [MEDIUM] CVE-2010-2937: vlc - The ReadMetaFromId3v2 function in taglib.cpp in the TagLib plugin in VideoLAN VL... The ReadMetaFromId3v2 function in taglib.cpp in the TagLib plugin in VideoLAN VLC media player 0.9.0 through 1.1.2 does not properly process ID3v2 tags, which allows remote attackers to cause a denial of service (application crash) via a crafted media file. Scope: local bookworm: resolved (fixed in 1.1.3-1) bullseye: resolved (fixed in 1.1.3-1) forky: resolved (fixed in
debian
CVE-2017-8310P4MEDIUMCVSS 5.5fixed in vlc 2.2.5.1-1~deb9u1 (bookworm)2017
CVE-2017-8310 [MEDIUM] CVE-2017-8310: vlc - Heap out-of-bound read in CreateHtmlSubtitle in VideoLAN VLC 2.2.x due to missin... Heap out-of-bound read in CreateHtmlSubtitle in VideoLAN VLC 2.2.x due to missing check of string termination allows attackers to read data beyond allocated memory and potentially crash the process (causing a denial of service) via a crafted subtitles file. Scope: local bookworm: resolved (fixed in 2.2.5.1-1~deb9u1) bullseye: resolved (fixed in 2.2.5.1-1~deb9u1) forky:
debian
Debian Vlc vulnerabilities | cvebase