Vulnerabilities
Vulnerable Software
The MP4_ReadBox_String function in modules/demux/mp4/libmp4.c in VideoLAN VLC media player before 2.1.6 performs an incorrect cast operation from a 64-bit integer to a 32-bit integer, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a large box size.
CVSS Score
7.8
EPSS Score
0.003
Published
2020-01-24
The MP4_ReadBox_String function in modules/demux/mp4/libmp4.c in VideoLAN VLC media player before 2.1.6 allows remote attackers to trigger an unintended zero-size malloc and conduct buffer overflow attacks, and consequently execute arbitrary code, via a box size of 7.
CVSS Score
7.8
EPSS Score
0.016
Published
2020-01-24
Integer overflow in the Encode function in modules/codec/schroedinger.c in VideoLAN VLC media player before 2.1.6 and 2.2.x before 2.2.1 allows remote attackers to conduct buffer overflow attacks and execute arbitrary code via a crafted length value.
CVSS Score
7.8
EPSS Score
0.045
Published
2020-01-24
The rtp_packetize_xiph_config function in modules/stream_out/rtpfmt.c in VideoLAN VLC media player before 2.1.6 uses a stack-allocation approach with a size determined by arbitrary input data, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted length value.
CVSS Score
7.8
EPSS Score
0.006
Published
2020-01-24
An Integer underflow in VLC Media Player versions < 3.0.7 leads to an out-of-band read.
CVSS Score
7.1
EPSS Score
0.009
Published
2019-07-30
Double Free in VLC versions <= 3.0.6 leads to a crash.
CVSS Score
5.5
EPSS Score
0.007
Published
2019-07-30
lavc_CopyPicture in modules/codec/avcodec/video.c in VideoLAN VLC media player through 3.0.7 has a heap-based buffer over-read because it does not properly validate the width and height.
CVSS Score
9.8
EPSS Score
0.019
Published
2019-07-18
libebml before 1.3.6, as used in the MKV module in VideoLAN VLC Media Player binaries before 3.0.3, has a heap-based buffer over-read in EbmlElement::FindNextElement.
CVSS Score
5.5
EPSS Score
0.003
Published
2019-07-16
An Integer Underflow in MP4_EIA608_Convert() in modules/demux/mp4/mp4.c in VideoLAN VLC media player through 3.0.7.1 allows remote attackers to cause a denial of service (heap-based buffer overflow and crash) or possibly have unspecified other impact via a crafted .mp4 file.
CVSS Score
7.8
EPSS Score
0.005
Published
2019-07-14
A Buffer Overflow in VLC Media Player < 3.0.7 causes a crash which can possibly be further developed into a remote code execution exploit.
CVSS Score
6.5
EPSS Score
0.158
Published
2019-06-13


Contact Us

Shodan ® - All rights reserved