Show filters
212 Total Results
Displaying 11-20 of 212
Sort by:
Attacker Value
Unknown

CVE-2022-36250

Disclosure Date: May 29, 2023 (last updated October 08, 2023)
Shop Beat Solutions (Pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to Cross Site Request Forgery (CSRF).
Attacker Value
Unknown

CVE-2022-36243

Disclosure Date: May 23, 2023 (last updated October 08, 2023)
Shop Beat Solutions (pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to Directory Traversal via server.shopbeat.co.za. Information Exposure Through Directory Listing vulnerability in "studio" software of Shop Beat. This issue affects: Shop Beat studio studio versions prior to 3.2.57 on arm.
Attacker Value
Unknown

CVE-2019-25086

Disclosure Date: December 27, 2022 (last updated October 08, 2023)
A vulnerability was found in IET-OU Open Media Player up to 1.5.0. It has been declared as problematic. This vulnerability affects the function webvtt of the file application/controllers/timedtext.php. The manipulation of the argument ttml_url leads to cross site scripting. The attack can be initiated remotely. Upgrading to version 1.5.1 is able to address this issue. The name of the patch is 3f39f2d68d11895929c04f7b49b97a734ae7cd1f. It is recommended to upgrade the affected component. VDB-216862 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2022-41325

Disclosure Date: December 06, 2022 (last updated October 08, 2023)
An integer overflow in the VNC module in VideoLAN VLC Media Player through 3.0.17.4 allows attackers, by tricking a user into opening a crafted playlist or connecting to a rogue VNC server, to crash VLC or execute code under some conditions.
Attacker Value
Unknown

CVE-2021-25804

Disclosure Date: July 26, 2021 (last updated February 23, 2025)
A NULL-pointer dereference in "Open" in avi.c of VideoLAN VLC Media Player 3.0.11 can a denial of service (DOS) in the application.
Attacker Value
Unknown

CVE-2021-25802

Disclosure Date: July 26, 2021 (last updated February 23, 2025)
A buffer overflow vulnerability in the AVI_ExtractSubtitle component of VideoLAN VLC Media Player 3.0.11 allows attackers to cause an out-of-bounds read via a crafted .avi file.
Attacker Value
Unknown

CVE-2021-25801

Disclosure Date: July 26, 2021 (last updated February 23, 2025)
A buffer overflow vulnerability in the __Parse_indx component of VideoLAN VLC Media Player 3.0.11 allows attackers to cause an out-of-bounds read via a crafted .avi file.
Attacker Value
Unknown

CVE-2021-25803

Disclosure Date: July 26, 2021 (last updated February 23, 2025)
A buffer overflow vulnerability in the vlc_input_attachment_New component of VideoLAN VLC Media Player 3.0.11 allows attackers to cause an out-of-bounds read via a crafted .avi file.
Attacker Value
Unknown

CVE-2020-26664

Disclosure Date: January 08, 2021 (last updated February 22, 2025)
A vulnerability in EbmlTypeDispatcher::send in VideoLAN VLC media player 3.0.11 allows attackers to trigger a heap-based buffer overflow via a crafted .mkv file.
Attacker Value
Unknown

CVE-2020-13428

Disclosure Date: June 08, 2020 (last updated February 21, 2025)
A heap-based buffer overflow in the hxxx_AnnexB_to_xVC function in modules/packetizer/hxxx_nal.c in VideoLAN VLC media player before 3.0.11 for macOS/iOS allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a crafted H.264 Annex-B video (.avi for example) file.