Show filters
113 Total Results
Displaying 101-110 of 113
Sort by:
Attacker Value
Unknown

CVE-2008-4558

Disclosure Date: October 15, 2008 (last updated October 04, 2023)
Array index error in VLC media player 0.9.2 allows remote attackers to overwrite arbitrary memory and execute arbitrary code via an XSPF playlist file with a negative identifier tag, which passes a signed comparison.
0
Attacker Value
Unknown

CVE-2008-3794

Disclosure Date: August 26, 2008 (last updated October 04, 2023)
Integer signedness error in the mms_ReceiveCommand function in modules/access/mms/mmstu.c in VLC Media Player 0.8.6i allows remote attackers to execute arbitrary code via a crafted mmst link with a negative size value, which bypasses a size check and triggers an integer overflow followed by a heap-based buffer overflow.
0
Attacker Value
Unknown

CVE-2008-3732

Disclosure Date: August 20, 2008 (last updated October 04, 2023)
Integer overflow in the Open function in modules/demux/tta.c in VLC Media Player 0.8.6i allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted TTA file, which triggers a heap-based buffer overflow. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2008-2430

Disclosure Date: July 07, 2008 (last updated October 04, 2023)
Integer overflow in the Open function in modules/demux/wav.c in VLC Media Player 0.8.6h on Windows allows remote attackers to execute arbitrary code via a large fmt chunk in a WAV file.
0
Attacker Value
Unknown

CVE-2008-0984

Disclosure Date: February 26, 2008 (last updated October 04, 2023)
The MP4 demuxer (mp4.c) for VLC media player 0.8.6d and earlier, as used in Miro Player 1.1 and earlier, allows remote attackers to overwrite arbitrary memory and execute arbitrary code via a malformed MP4 file.
0
Attacker Value
Unknown

CVE-2008-0295

Disclosure Date: January 16, 2008 (last updated October 04, 2023)
Heap-based buffer overflow in modules/access/rtsp/real_sdpplin.c in the Xine library, as used in VideoLAN VLC Media Player 0.8.6d and earlier, allows user-assisted remote attackers to cause a denial of service (crash) or execute arbitrary code via long Session Description Protocol (SDP) data.
0
Attacker Value
Unknown

CVE-2008-0296

Disclosure Date: January 16, 2008 (last updated October 04, 2023)
Heap-based buffer overflow in the libaccess_realrtsp plugin in VideoLAN VLC Media Player 0.8.6d and earlier on Windows might allow remote RTSP servers to cause a denial of service (application crash) or execute arbitrary code via a long string.
0
Attacker Value
Unknown

CVE-2007-6262

Disclosure Date: December 06, 2007 (last updated October 04, 2023)
A certain ActiveX control in axvlc.dll in VideoLAN VLC 0.8.6 before 0.8.6d allows remote attackers to execute arbitrary code via crafted arguments to the (1) addTarget, (2) getVariable, or (3) setVariable function, resulting from a "bad initialized pointer," aka a "recursive plugin release vulnerability."
0
Attacker Value
Unknown

CVE-2007-3468

Disclosure Date: June 27, 2007 (last updated October 04, 2023)
input.c in VideoLAN VLC Media Player before 0.8.6c allows remote attackers to cause a denial of service (crash) via a crafted WAV file that causes an uninitialized i_nb_resamplers variable to be used.
0
Attacker Value
Unknown

CVE-2007-3467

Disclosure Date: June 27, 2007 (last updated October 04, 2023)
Integer overflow in the __status_Update function in stats.c VideoLAN VLC Media Player before 0.8.6c allows remote attackers to cause a denial of service (crash) via a WAV file with a large sample rate.
0