Videolan Vlc Media Player vulnerabilities
135 known vulnerabilities affecting videolan/vlc_media_player.
Total CVEs
135
CISA KEV
0
Public exploits
40
Exploited in wild
0
Severity breakdown
CRITICAL32HIGH59MEDIUM44
Vulnerabilities
Page 4 of 7
CVE-2015-5949MEDIUMCVSS 6.8≤ 2.2.12015-08-25
CVE-2015-5949 [MEDIUM] CWE-119 CVE-2015-5949: VideoLAN VLC media player 2.2.1 allows remote attackers to cause a denial of service (crash) and pos
VideoLAN VLC media player 2.2.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted 3GP file, which triggers the freeing of arbitrary pointers.
nvdosv
CVE-2014-9743MEDIUMCVSS 4.3≤ 2.1.62015-08-17
CVE-2014-9743 [MEDIUM] CWE-79 CVE-2014-9743: Cross-site scripting (XSS) vulnerability in the httpd_HtmlError function in network/httpd.c in the w
Cross-site scripting (XSS) vulnerability in the httpd_HtmlError function in network/httpd.c in the web interface in VideoLAN VLC Media Player before 2.2.0 allows remote attackers to inject arbitrary web script or HTML via the path info.
nvdosv
CVE-2014-9597MEDIUMCVSS 6.8PoCv2.1.52015-01-21
CVE-2014-9597 [MEDIUM] CWE-20 CVE-2014-9597: The picture_pool_Delete function in misc/picture_pool.c in VideoLAN VLC media player 2.1.5 allows re
The picture_pool_Delete function in misc/picture_pool.c in VideoLAN VLC media player 2.1.5 allows remote attackers to execute arbitrary code or cause a denial of service (DEP violation and application crash) via a crafted FLV file.
nvdosv
CVE-2014-9598MEDIUMCVSS 6.8PoCv2.1.52015-01-21
CVE-2014-9598 [MEDIUM] CWE-20 CVE-2014-9598: The picture_Release function in misc/picture.c in VideoLAN VLC media player 2.1.5 allows remote atta
The picture_Release function in misc/picture.c in VideoLAN VLC media player 2.1.5 allows remote attackers to execute arbitrary code or cause a denial of service (write access violation) via a crafted M2V file.
nvd
CVE-2010-1444HIGHCVSS 7.5≤ 1.0.5v0.5.0+42 more2014-12-26
CVE-2010-1444 [HIGH] CWE-119 CVE-2010-1444: The ZIP archive decompressor in VideoLAN VLC media player before 1.0.6 allows remote attackers to ca
The ZIP archive decompressor in VideoLAN VLC media player before 1.0.6 allows remote attackers to cause a denial of service (invalid memory access and application crash) or possibly execute arbitrary code via a crafted archive.
nvdosv
CVE-2011-3623HIGHCVSS 7.5≤ 1.0.1v0.5.0+38 more2014-12-26
CVE-2011-3623 [HIGH] CWE-119 CVE-2011-3623: Multiple stack-based buffer overflows in VideoLAN VLC media player before 1.0.2 allow remote attacke
Multiple stack-based buffer overflows in VideoLAN VLC media player before 1.0.2 allow remote attackers to execute arbitrary code via (1) a crafted ASF file, related to the ASF_ObjectDumpDebug function in modules/demux/asf/libasf.c; (2) a crafted AVI file, related to the AVI_ChunkDumpDebug_level function in modules/demux/avi/libavi.c; or (3) a crafted MP
nvdosv
CVE-2010-2062HIGHCVSS 7.5≤ 1.0.0v0.5.0+37 more2014-12-26
CVE-2010-2062 [HIGH] CWE-189 CVE-2010-2062: Integer underflow in the real_get_rdt_chunk function in real.c, as used in modules/access/rtsp/real.
Integer underflow in the real_get_rdt_chunk function in real.c, as used in modules/access/rtsp/real.c in VideoLAN VLC media player before 1.0.1 and stream/realrtsp/real.c in MPlayer before r29447, allows remote attackers to execute arbitrary code via a crafted length value in an RDT chunk header.
nvdosv
CVE-2010-1442HIGHCVSS 7.5≤ 1.0.5v0.5.0+42 more2014-12-26
CVE-2010-1442 [HIGH] CWE-119 CVE-2010-1442: VideoLAN VLC media player before 1.0.6 allows remote attackers to cause a denial of service (invalid
VideoLAN VLC media player before 1.0.6 allows remote attackers to cause a denial of service (invalid memory access and application crash) or possibly execute arbitrary code via a crafted byte stream to the (1) AVI, (2) ASF, or (3) Matroska (aka MKV) demuxer.
nvdosv
CVE-2010-1445HIGHCVSS 7.5≤ 1.0.5v0.5.0+42 more2014-12-26
CVE-2010-1445 [HIGH] CWE-119 CVE-2010-1445: Heap-based buffer overflow in VideoLAN VLC media player before 1.0.6 allows remote attackers to caus
Heap-based buffer overflow in VideoLAN VLC media player before 1.0.6 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted byte stream in an RTMP session.
nvdosv
CVE-2010-1441HIGHCVSS 7.5≤ 1.0.5v0.5.0+42 more2014-12-26
CVE-2010-1441 [HIGH] CWE-119 CVE-2010-1441: Multiple heap-based buffer overflows in VideoLAN VLC media player before 1.0.6 allow remote attacker
Multiple heap-based buffer overflows in VideoLAN VLC media player before 1.0.6 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted byte stream to the (1) A/52, (2) DTS, or (3) MPEG Audio decoder.
nvdosv
CVE-2010-1443MEDIUMCVSS 5.0≤ 1.0.5v0.5.0+42 more2014-12-26
CVE-2010-1443 [MEDIUM] CVE-2010-1443: The parse_track_node function in modules/demux/playlist/xspf.c in the XSPF playlist parser in VideoL
The parse_track_node function in modules/demux/playlist/xspf.c in the XSPF playlist parser in VideoLAN VLC media player before 1.0.6 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an empty location element in an XML Shareable Playlist Format (XSPF) document.
nvdosv
CVE-2014-3441MEDIUMCVSS 4.3PoCv2.1.32014-05-14
CVE-2014-3441 [MEDIUM] CWE-119 CVE-2014-3441: codec\libpng_plugin.dll in VideoLAN VLC Media Player 2.1.3 allows remote attackers to cause a denial
codec\libpng_plugin.dll in VideoLAN VLC Media Player 2.1.3 allows remote attackers to cause a denial of service (crash) via a crafted .png file, as demonstrated by a png in a .wave file.
nvd
CVE-2013-7340MEDIUMCVSS 4.3≤ 2.0.6v0.1.99a+103 more2014-03-21
CVE-2013-7340 [MEDIUM] CWE-399 CVE-2013-7340: VideoLAN VLC Media Player before 2.0.7 allows remote attackers to cause a denial of service (memory
VideoLAN VLC Media Player before 2.0.7 allows remote attackers to cause a denial of service (memory consumption) via a crafted playlist file.
nvdosv
CVE-2014-1684MEDIUMCVSS 4.3PoC≤ 2.1.2v1.0.0+35 more2014-03-03
CVE-2014-1684 [MEDIUM] CWE-189 CVE-2014-1684: The ASF_ReadObject_file_properties function in modules/demux/asf/libasf.c in the ASF Demuxer in Vide
The ASF_ReadObject_file_properties function in modules/demux/asf/libasf.c in the ASF Demuxer in VideoLAN VLC Media Player before 2.1.3 allows remote attackers to cause a denial of service (divide-by-zero error and crash) via a zero minimum and maximum data packet size in an ASF file.
nvdosv
CVE-2013-6933HIGHCVSS 7.5≥ 0, < 2.1.4-12014-01-23
CVE-2013-6933 [HIGH] CVE-2013-6933: The parseRTSPRequestString function in Live Networks Live555 Streaming Media 2011
The parseRTSPRequestString function in Live Networks Live555 Streaming Media 2011.08.13 through 2013.11.25, as used in VideoLAN VLC Media Player, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a (1) space or (2) tab character at the beginning of an RTSP message, which triggers an integer underflow, infinite loop, and buffer ov
osv
CVE-2013-6934HIGHCVSS 7.5fixed in 2.1.02014-01-23
CVE-2013-6934 [HIGH] CVE-2013-6934: The parseRTSPRequestString function in Live Networks Live555 Streaming Media 2013.11.26, as used in
The parseRTSPRequestString function in Live Networks Live555 Streaming Media 2013.11.26, as used in VideoLAN VLC Media Player, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a space character at the beginning of an RTSP message, which triggers an integer underflow, infinite loop, and buffer overflow. NOTE: th
nvd
CVE-2013-6283HIGHCVSS 7.5PoC≤ 2.0.8v1.0.0+31 more2013-10-25
CVE-2013-6283 [HIGH] CWE-20 CVE-2013-6283: VideoLAN VLC Media Player 2.0.8 and earlier allows remote attackers to cause a denial of service (cr
VideoLAN VLC Media Player 2.0.8 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in a URL in a m3u file.
nvdosv
CVE-2013-4388MEDIUMCVSS 6.8≤ 2.0.7v2.0.0+6 more2013-10-11
CVE-2013-4388 [MEDIUM] CWE-119 CVE-2013-4388: Buffer overflow in the mp4a packetizer (modules/packetizer/mpeg4audio.c) in VideoLAN VLC Media Playe
Buffer overflow in the mp4a packetizer (modules/packetizer/mpeg4audio.c) in VideoLAN VLC Media Player before 2.0.8 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors.
nvdosv
CVE-2013-1868CRITICALCVSS 9.3PoC≤ 2.0.4v2.0.0+3 more2013-07-10
CVE-2013-1868 [CRITICAL] CWE-119 CVE-2013-1868: Multiple buffer overflows in VideoLAN VLC media player 2.0.4 and earlier allow remote attackers to c
Multiple buffer overflows in VideoLAN VLC media player 2.0.4 and earlier allow remote attackers to cause a denial of service (crash) and execute arbitrary code via vectors related to the (1) freetype renderer and (2) HTML subtitle parser.
nvdosv
CVE-2012-5855MEDIUMCVSS 4.3≤ 2.0.4v2.0.0+3 more2013-07-10
CVE-2012-5855 [MEDIUM] CWE-189 CVE-2012-5855: The SHAddToRecentDocs function in VideoLAN VLC media player 2.0.4 and earlier might allow user-assis
The SHAddToRecentDocs function in VideoLAN VLC media player 2.0.4 and earlier might allow user-assisted attackers to cause a denial of service (crash) via a crafted file name that triggers an incorrect string-length calculation when the file is added to VLC. NOTE: it is not clear whether this issue crosses privilege boundaries or whether it can be exp
nvd