CVE-2020-26664 |
AVG-1423 |
Medium |
No |
Arbitrary code execution |
A vulnerability in EbmlTypeDispatcher::send in VideoLAN VLC media player 3.0.11 allows attackers to trigger a heap-based buffer overflow via a crafted .mkv... |
CVE-2019-19721 |
AVG-1145 |
Medium |
Yes |
Denial of service |
An off-by-one error in the DecodeBlock function in codec/sdl_image.c in VideoLAN VLC media player before 3.0.9 allows remote attackers to cause a denial of... |
CVE-2019-13615 |
AVG-1008 |
Medium |
Yes |
Information disclosure |
Not an issue in vlc, the issue was in libebml and was fixed in 1.3.6. |
CVE-2019-12874 |
AVG-998 |
Critical |
Yes |
Arbitrary code execution |
VideoLAN VLC media player 3.0.6 and earlier has a double-free in the zlib_decompress_extra function of the Matroska demuxer in modules/demux/mkv/util.cpp. |
CVE-2019-5439 |
AVG-998 |
Critical |
Yes |
Arbitrary code execution |
VideoLAN VLC media player 3.0.6 and earlier has a out-of-bounds write has been found in the ReadFrame function of the AVI decoder. |
CVE-2018-11529 |
AVG-755 |
High |
No |
Arbitrary code execution |
VideoLAN VLC media player 2.2.x before 3.0.3-1 is prone to a use after free vulnerability which an attacker can leverage to execute arbitrary code via... |
CVE-2017-10699 |
AVG-533 |
Critical |
Yes |
Arbitrary code execution |
It was discovered that avcodec 2.2.x, as used in VideoLAN VLC media player before 2.2.7, allows out-of-bounds heap memory write due to calling memcpy() with... |
CVE-2017-9300 |
AVG-533 |
High |
Yes |
Arbitrary code execution |
It was discovered that plugins\codec\libflac_plugin.so in VideoLAN VLC media player before 2.2.7 allows remote attackers to cause a heap corruption and... |
CVE-2017-8312 |
AVG-283 |
Medium |
No |
Denial of service |
Heap out-of-bound read in ParseJSS in VideoLAN VLC due to missing check of string length allows attackers to read heap uninitialized data via a crafted... |
CVE-2017-8311 |
AVG-283 |
High |
No |
Arbitrary code execution |
Potential heap based buffer overflow in ParseJSS in VideoLAN VLC before 2.2.5 due to skipping NULL terminator in an input string allows attackers to execute... |
CVE-2017-8310 |
AVG-283 |
Medium |
No |
Denial of service |
Heap out-of-bound read in CreateHtmlSubtitle in VideoLAN VLC 2.2.x due to missing check of string termination allows attackers to read data beyond allocated... |