Show filters
113 Total Results
Displaying 41-50 of 113
Sort by:
Attacker Value
Unknown

CVE-2017-17670

Disclosure Date: December 15, 2017 (last updated November 26, 2024)
In VideoLAN VLC media player through 2.2.8, there is a type conversion vulnerability in modules/demux/mp4/libmp4.c in the MP4 demux module leading to a invalid free, because the type of a box may be changed between a read operation and a free operation.
0
Attacker Value
Unknown

CVE-2017-10699

Disclosure Date: June 30, 2017 (last updated November 26, 2024)
avcodec 2.2.x, as used in VideoLAN VLC media player 2.2.7-x before 2017-06-29, allows out-of-bounds heap memory write due to calling memcpy() with a wrong size, leading to a denial of service (application crash) or possibly code execution.
0
Attacker Value
Unknown

CVE-2017-9300

Disclosure Date: May 29, 2017 (last updated November 26, 2024)
plugins\codec\libflac_plugin.dll in VideoLAN VLC media player 2.2.4 allows remote attackers to cause a denial of service (heap corruption and application crash) or possibly have unspecified other impact via a crafted FLAC file.
0
Attacker Value
Unknown

CVE-2017-9301

Disclosure Date: May 29, 2017 (last updated November 26, 2024)
plugins\audio_filter\libmpgatofixed32_plugin.dll in VideoLAN VLC media player 2.2.4 allows remote attackers to cause a denial of service (invalid read and application crash) or possibly have unspecified other impact via a crafted file.
0
Attacker Value
Unknown

CVE-2017-8313

Disclosure Date: May 23, 2017 (last updated November 08, 2023)
Heap out-of-bound read in ParseJSS in VideoLAN VLC before 2.2.5 due to missing check of string termination allows attackers to read data beyond allocated memory and potentially crash the process via a crafted subtitles file.
0
Attacker Value
Unknown

CVE-2017-8311

Disclosure Date: May 23, 2017 (last updated November 08, 2023)
Potential heap based buffer overflow in ParseJSS in VideoLAN VLC before 2.2.5 due to skipping NULL terminator in an input string allows attackers to execute arbitrary code via a crafted subtitles file.
0
Attacker Value
Unknown

CVE-2017-8312

Disclosure Date: May 23, 2017 (last updated November 08, 2023)
Heap out-of-bound read in ParseJSS in VideoLAN VLC due to missing check of string length allows attackers to read heap uninitialized data via a crafted subtitles file.
0
Attacker Value
Unknown

CVE-2017-8310

Disclosure Date: May 23, 2017 (last updated November 08, 2023)
Heap out-of-bound read in CreateHtmlSubtitle in VideoLAN VLC 2.2.x due to missing check of string termination allows attackers to read data beyond allocated memory and potentially crash the process (causing a denial of service) via a crafted subtitles file.
0
Attacker Value
Unknown

CVE-2016-5108

Disclosure Date: June 08, 2016 (last updated November 25, 2024)
Buffer overflow in the DecodeAdpcmImaQT function in modules/codec/adpcm.c in VideoLAN VLC media player before 2.2.4 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted QuickTime IMA file.
0
Attacker Value
Unknown

CVE-2016-3941

Disclosure Date: April 18, 2016 (last updated November 25, 2024)
Buffer overflow in the AStreamPeekStream function in input/stream.c in VideoLAN VLC media player before 2.2.0 allows remote attackers to cause a denial of service (crash) via a crafted wav file, related to "seek across EOF."
0