Videolan Vlc Media Player vulnerabilities
135 known vulnerabilities affecting videolan/vlc_media_player.
Total CVEs
135
CISA KEV
0
Public exploits
40
Exploited in wild
0
Severity breakdown
CRITICAL32HIGH59MEDIUM44
Vulnerabilities
Page 5 of 7
CVE-2013-1954MEDIUMCVSS 6.8≤ 2.0.5v2.0.0+4 more2013-07-10
CVE-2013-1954 [MEDIUM] CWE-119 CVE-2013-1954: The ASF Demuxer (modules/demux/asf/asf.c) in VideoLAN VLC media player 2.0.5 and earlier allows remo
The ASF Demuxer (modules/demux/asf/asf.c) in VideoLAN VLC media player 2.0.5 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted ASF movie that triggers an out-of-bounds read.
nvdosv
CVE-2013-3245MEDIUMCVSS 6.3v2.0.72013-07-10
CVE-2013-3245 [MEDIUM] CWE-119 CVE-2013-3245: plugins/demux/libmkv_plugin.dll in VideoLAN VLC Media Player 2.0.7, and possibly other versions, all
plugins/demux/libmkv_plugin.dll in VideoLAN VLC Media Player 2.0.7, and possibly other versions, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted MKV file, possibly involving an integer overflow and out-of-bounds read or heap-based buffer overflow, or an uncaught exception. NOTE: the vendor
nvdosv
CVE-2012-0023CRITICALCVSS 9.3v0.9.0v0.9.1+32 more2012-10-30
CVE-2012-0023 [CRITICAL] CWE-399 CVE-2012-0023: Double free vulnerability in the get_chunk_header function in modules/demux/ty.c in VideoLAN VLC med
Double free vulnerability in the get_chunk_header function in modules/demux/ty.c in VideoLAN VLC media player 0.9.0 through 1.1.12 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TiVo (TY) file.
nvdosv
CVE-2012-5470MEDIUMCVSS 4.3PoCv2.0.32012-10-26
CVE-2012-5470 [MEDIUM] CWE-119 CVE-2012-5470: libpng_plugin in VideoLAN VLC media player 2.0.3 allows remote attackers to cause a denial of servic
libpng_plugin in VideoLAN VLC media player 2.0.3 allows remote attackers to cause a denial of service (application crash) via a crafted PNG file.
nvdosv
CVE-2012-3377MEDIUMCVSS 6.8≤ 2.0.1v0.1.99a+97 more2012-07-12
CVE-2012-3377 [MEDIUM] CWE-119 CVE-2012-3377: Heap-based buffer overflow in the Ogg_DecodePacket function in the OGG demuxer (modules/demux/ogg.c)
Heap-based buffer overflow in the Ogg_DecodePacket function in the OGG demuxer (modules/demux/ogg.c) in VideoLAN VLC media player before 2.0.2 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted OGG file.
nvdosv
CVE-2012-2396MEDIUMCVSS 4.3PoCv2.0.12012-04-19
CVE-2012-2396 [MEDIUM] CVE-2012-2396: VideoLAN VLC media player 2.0.1 allows remote attackers to cause a denial of service (divide-by-zero
VideoLAN VLC media player 2.0.1 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted MP4 file.
nvd
CVE-2012-1775CRITICALCVSS 9.3PoC≤ 2.0.0v0.1.99a+100 more2012-03-19
CVE-2012-1775 [CRITICAL] CWE-119 CVE-2012-1775: Stack-based buffer overflow in VideoLAN VLC media player before 2.0.1 allows remote attackers to exe
Stack-based buffer overflow in VideoLAN VLC media player before 2.0.1 allows remote attackers to execute arbitrary code via a crafted MMS:// stream.
nvdosv
CVE-2012-1776CRITICALCVSS 9.3≤ 2.0.0v0.1.99a+100 more2012-03-19
CVE-2012-1776 [CRITICAL] CWE-119 CVE-2012-1776: Multiple heap-based buffer overflows in VideoLAN VLC media player before 2.0.1 allow remote attacker
Multiple heap-based buffer overflows in VideoLAN VLC media player before 2.0.1 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted Real RTSP stream.
nvdosv
CVE-2012-0904MEDIUMCVSS 4.3PoCv1.1.112012-01-20
CVE-2012-0904 [MEDIUM] CWE-399 CVE-2012-0904: VLC media player 1.1.11 allows remote attackers to cause a denial of service (crash) via a long stri
VLC media player 1.1.11 allows remote attackers to cause a denial of service (crash) via a long string in an amr file.
nvd
CVE-2011-2587MEDIUMCVSS 6.8v1.1.0v1.1.1+12 more2011-07-27
CVE-2011-2587 [MEDIUM] CWE-119 CVE-2011-2587: Heap-based buffer overflow in the DemuxAudioSipr function in real.c in the RealMedia demuxer in Vide
Heap-based buffer overflow in the DemuxAudioSipr function in real.c in the RealMedia demuxer in VideoLAN VLC media player 1.1.x before 1.1.11 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted Real Media file.
nvdosv
CVE-2011-2588MEDIUMCVSS 6.8≤ 1.1.10.1v0.1.99b+72 more2011-07-27
CVE-2011-2588 [MEDIUM] CWE-119 CVE-2011-2588: Heap-based buffer overflow in the AVI_ChunkRead_strf function in libavi.c in the AVI demuxer in Vide
Heap-based buffer overflow in the AVI_ChunkRead_strf function in libavi.c in the AVI demuxer in VideoLAN VLC media player before 1.1.11 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted AVI media file.
nvdosv
CVE-2011-1931MEDIUMCVSS 6.8≤ 1.1.9v0.1.99b+70 more2011-07-07
CVE-2011-1931 [MEDIUM] CWE-119 CVE-2011-1931: sp5xdec.c in the Sunplus SP5X JPEG decoder in libavcodec in FFmpeg before 0.6.3 and libav through 0.
sp5xdec.c in the Sunplus SP5X JPEG decoder in libavcodec in FFmpeg before 0.6.3 and libav through 0.6.2, as used in VideoLAN VLC media player 1.1.9 and earlier and other products, performs a write operation outside the bounds of an unspecified array, which allows remote attackers to cause a denial of service (memory corruption) or possibly execute arb
nvd
CVE-2011-2194CRITICALCVSS 9.3PoCv0.8.5v0.8.6+38 more2011-06-24
CVE-2011-2194 [CRITICAL] CWE-189 CVE-2011-2194: Integer overflow in the XSPF playlist parser in VideoLAN VLC media player 0.8.5 through 1.1.9 allows
Integer overflow in the XSPF playlist parser in VideoLAN VLC media player 0.8.5 through 1.1.9 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors that trigger a heap-based buffer overflow.
nvdosv
CVE-2011-1087HIGHCVSS 7.6v1.0.52011-05-03
CVE-2011-1087 [HIGH] CWE-119 CVE-2011-1087: Buffer overflow in VideoLAN VLC media player 1.0.5 allows user-assisted remote attackers to cause a
Buffer overflow in VideoLAN VLC media player 1.0.5 allows user-assisted remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted .mp3 file that is played during bookmark creation.
nvdosv
CVE-2011-1684MEDIUMCVSS 6.8v1.0.0v1.0.1+15 more2011-05-03
CVE-2011-1684 [MEDIUM] CWE-119 CVE-2011-1684: Heap-based buffer overflow in the MP4_ReadBox_skcr function in libmp4.c in the MP4 demultiplexer in
Heap-based buffer overflow in the MP4_ReadBox_skcr function in libmp4.c in the MP4 demultiplexer in VideoLAN VLC media player 1.x before 1.1.9 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted MP4 file.
nvdosv
CVE-2010-3275CRITICALCVSS 9.3PoC≤ 1.1.7v0.1.99b+68 more2011-03-28
CVE-2010-3275 [CRITICAL] CWE-119 CVE-2010-3275: libdirectx_plugin.dll in VideoLAN VLC Media Player before 1.1.8 allows remote attackers to execute a
libdirectx_plugin.dll in VideoLAN VLC Media Player before 1.1.8 allows remote attackers to execute arbitrary code via a crafted width in an AMV file, related to a "dangling pointer vulnerability."
nvdosv
CVE-2010-3276CRITICALCVSS 9.3≤ 1.1.7v0.1.99b+68 more2011-03-28
CVE-2010-3276 [CRITICAL] CWE-119 CVE-2010-3276: libdirectx_plugin.dll in VideoLAN VLC Media Player before 1.1.8 allows remote attackers to execute a
libdirectx_plugin.dll in VideoLAN VLC Media Player before 1.1.8 allows remote attackers to execute arbitrary code via a crafted width in an NSV file.
nvdosv
CVE-2011-0531CRITICALCVSS 9.3PoC≤ 1.1.6.1v0.1.99b+67 more2011-02-07
CVE-2011-0531 [CRITICAL] CWE-20 CVE-2011-0531: demux/mkv/mkv.hpp in the MKV demuxer plugin in VideoLAN VLC media player 1.1.6.1 and earlier allows
demux/mkv/mkv.hpp in the MKV demuxer plugin in VideoLAN VLC media player 1.1.6.1 and earlier allows remote attackers to cause a denial of service (crash) and execute arbitrary commands via a crafted MKV (WebM or Matroska) file that triggers memory corruption, related to "class mismatching" and the MKV_IS_ID macro.
nvdosv
CVE-2011-0522MEDIUMCVSS 6.8PoCv1.1.0v1.1.1+5 more2011-02-07
CVE-2011-0522 [MEDIUM] CWE-119 CVE-2011-0522: The StripTags function in (1) the USF decoder (modules/codec/subtitles/subsdec.c) and (2) the Text d
The StripTags function in (1) the USF decoder (modules/codec/subtitles/subsdec.c) and (2) the Text decoder (modules/codec/subtitles/subsusf.c) in VideoLAN VLC Media Player 1.1 before 1.1.6-rc allows remote attackers to execute arbitrary code via a subtitle with an opening "" in an MKV file, which triggers heap memory corruption, as demonstrated using
nvdosv
CVE-2011-0021CRITICALCVSS 9.3≤ 1.1.5v0.1.99b+65 more2011-01-25
CVE-2011-0021 [CRITICAL] CWE-119 CVE-2011-0021: Multiple heap-based buffer overflows in cdg.c in the CDG decoder in VideoLAN VLC Media Player before
Multiple heap-based buffer overflows in cdg.c in the CDG decoder in VideoLAN VLC Media Player before 1.1.6 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted CDG video.
nvdosv