Show filters
127 Total Results
Displaying 101-110 of 127
Sort by:
Attacker Value
Unknown

CVE-2008-5276

Disclosure Date: December 03, 2008 (last updated October 04, 2023)
Integer overflow in the ReadRealIndex function in real.c in the Real demuxer plugin in VideoLAN VLC media player 0.9.0 through 0.9.7 allows remote attackers to execute arbitrary code via a malformed RealMedia (.rm) file that triggers a heap-based buffer overflow.
0
Attacker Value
Unknown

CVE-2008-5036

Disclosure Date: November 10, 2008 (last updated October 04, 2023)
Stack-based buffer overflow in VideoLAN VLC media player 0.9.x before 0.9.6 might allow user-assisted attackers to execute arbitrary code via an an invalid RealText (rt) subtitle file, related to the ParseRealText function in modules/demux/subtitle.c. NOTE: this issue was SPLIT from CVE-2008-5032 on 20081110.
0
Attacker Value
Unknown

CVE-2008-5032

Disclosure Date: November 10, 2008 (last updated October 04, 2023)
Stack-based buffer overflow in VideoLAN VLC media player 0.5.0 through 0.9.5 might allow user-assisted attackers to execute arbitrary code via the header of an invalid CUE image file, related to modules/access/vcd/cdrom.c. NOTE: this identifier originally included an issue related to RealText, but that issue has been assigned a separate identifier, CVE-2008-5036.
0
Attacker Value
Unknown

CVE-2008-4686

Disclosure Date: October 22, 2008 (last updated October 04, 2023)
Multiple integer overflows in ty.c in the TY demux plugin (aka the TiVo demuxer) in VideoLAN VLC media player, probably 0.9.4, might allow remote attackers to execute arbitrary code via a crafted .ty file, a different vulnerability than CVE-2008-4654.
0
Attacker Value
Unknown

CVE-2008-4654

Disclosure Date: October 22, 2008 (last updated October 04, 2023)
Stack-based buffer overflow in the parse_master function in the Ty demux plugin (modules/demux/ty.c) in VLC Media Player 0.9.0 through 0.9.4 allows remote attackers to execute arbitrary code via a TiVo TY media file with a header containing a crafted size value.
0
Attacker Value
Unknown

CVE-2008-4558

Disclosure Date: October 15, 2008 (last updated October 04, 2023)
Array index error in VLC media player 0.9.2 allows remote attackers to overwrite arbitrary memory and execute arbitrary code via an XSPF playlist file with a negative identifier tag, which passes a signed comparison.
0
Attacker Value
Unknown

CVE-2008-3794

Disclosure Date: August 26, 2008 (last updated October 04, 2023)
Integer signedness error in the mms_ReceiveCommand function in modules/access/mms/mmstu.c in VLC Media Player 0.8.6i allows remote attackers to execute arbitrary code via a crafted mmst link with a negative size value, which bypasses a size check and triggers an integer overflow followed by a heap-based buffer overflow.
0
Attacker Value
Unknown

CVE-2008-3732

Disclosure Date: August 20, 2008 (last updated October 04, 2023)
Integer overflow in the Open function in modules/demux/tta.c in VLC Media Player 0.8.6i allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted TTA file, which triggers a heap-based buffer overflow. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2008-2430

Disclosure Date: July 07, 2008 (last updated October 04, 2023)
Integer overflow in the Open function in modules/demux/wav.c in VLC Media Player 0.8.6h on Windows allows remote attackers to execute arbitrary code via a large fmt chunk in a WAV file.
0
Attacker Value
Unknown

CVE-2008-2147

Disclosure Date: May 12, 2008 (last updated October 04, 2023)
Untrusted search path vulnerability in VideoLAN VLC before 0.9.0 allows local users to execute arbitrary code via a malicious library under the modules/ or plugins/ subdirectories of the current working directory.
0