Show filters
36 Total Results
Displaying 21-30 of 36
Sort by:
Attacker Value
Unknown

CVE-2010-0364

Disclosure Date: January 21, 2010 (last updated October 04, 2023)
Stack-based buffer overflow in VideoLAN VLC Media Player 0.8.6 allows user-assisted remote attackers to execute arbitrary code via an ogg file with a crafted Advanced SubStation Alpha Subtitle (.ass) file, probably involving the Dialogue field.
0
Attacker Value
Unknown

CVE-2008-5032

Disclosure Date: November 10, 2008 (last updated October 04, 2023)
Stack-based buffer overflow in VideoLAN VLC media player 0.5.0 through 0.9.5 might allow user-assisted attackers to execute arbitrary code via the header of an invalid CUE image file, related to modules/access/vcd/cdrom.c. NOTE: this identifier originally included an issue related to RealText, but that issue has been assigned a separate identifier, CVE-2008-5036.
0
Attacker Value
Unknown

CVE-2008-3794

Disclosure Date: August 26, 2008 (last updated October 04, 2023)
Integer signedness error in the mms_ReceiveCommand function in modules/access/mms/mmstu.c in VLC Media Player 0.8.6i allows remote attackers to execute arbitrary code via a crafted mmst link with a negative size value, which bypasses a size check and triggers an integer overflow followed by a heap-based buffer overflow.
0
Attacker Value
Unknown

CVE-2008-3732

Disclosure Date: August 20, 2008 (last updated October 04, 2023)
Integer overflow in the Open function in modules/demux/tta.c in VLC Media Player 0.8.6i allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted TTA file, which triggers a heap-based buffer overflow. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2008-2430

Disclosure Date: July 07, 2008 (last updated October 04, 2023)
Integer overflow in the Open function in modules/demux/wav.c in VLC Media Player 0.8.6h on Windows allows remote attackers to execute arbitrary code via a large fmt chunk in a WAV file.
0
Attacker Value
Unknown

CVE-2008-2147

Disclosure Date: May 12, 2008 (last updated October 04, 2023)
Untrusted search path vulnerability in VideoLAN VLC before 0.9.0 allows local users to execute arbitrary code via a malicious library under the modules/ or plugins/ subdirectories of the current working directory.
0
Attacker Value
Unknown

CVE-2008-1769

Disclosure Date: April 25, 2008 (last updated October 04, 2023)
VLC before 0.8.6f allow remote attackers to cause a denial of service (crash) via a crafted Cinepak file that triggers an out-of-bounds array access and memory corruption.
0
Attacker Value
Unknown

CVE-2008-1768

Disclosure Date: April 25, 2008 (last updated October 04, 2023)
Multiple integer overflows in VLC before 0.8.6f allow remote attackers to cause a denial of service (crash) via the (1) MP4 demuxer, (2) Real demuxer, and (3) Cinepak codec, which triggers a buffer overflow.
0
Attacker Value
Unknown

CVE-2008-1881

Disclosure Date: April 17, 2008 (last updated October 04, 2023)
Stack-based buffer overflow in the ParseSSA function (modules/demux/subtitle.c) in VLC 0.8.6e allows remote attackers to execute arbitrary code via a long subtitle in an SSA file. NOTE: this issue is due to an incomplete fix for CVE-2007-6681.
0
Attacker Value
Unknown

CVE-2008-1489

Disclosure Date: March 25, 2008 (last updated October 04, 2023)
Integer overflow in the MP4_ReadBox_rdrf function in libmp4.c for VLC 0.8.6e allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted MP4 RDRF box that triggers a heap-based buffer overflow, a different vulnerability than CVE-2008-0984.
0