Show filters
127 Total Results
Displaying 41-50 of 127
Sort by:
Attacker Value
Unknown
CVE-2018-19937
Disclosure Date: December 31, 2018 (last updated November 27, 2024)
A local, authenticated attacker can bypass the passcode in the VideoLAN VLC media player app before 3.1.5 for iOS by opening a URL and turning the phone.
0
Attacker Value
Unknown
CVE-2018-19857
Disclosure Date: December 05, 2018 (last updated November 08, 2023)
The CAF demuxer in modules/demux/caf.c in VideoLAN VLC media player 3.0.4 may read memory from an uninitialized pointer when processing magic cookies in CAF files, because a ReadKukiChunk() cast converts a return value to an unsigned int even if that value is negative. This could result in a denial of service and/or a potential infoleak.
0
Attacker Value
Unknown
CVE-2018-11529
Disclosure Date: July 11, 2018 (last updated November 27, 2024)
VideoLAN VLC media player 2.2.x is prone to a use after free vulnerability which an attacker can leverage to execute arbitrary code via crafted MKV files. Failed exploit attempts will likely result in denial of service conditions.
0
Attacker Value
Unknown
CVE-2018-11516
Disclosure Date: May 28, 2018 (last updated November 26, 2024)
The vlc_demux_chained_Delete function in input/demux_chained.c in VideoLAN VLC media player 3.0.1 allows remote attackers to cause a denial of service (heap corruption and application crash) or possibly have unspecified other impact via a crafted .swf file.
0
Attacker Value
Unknown
CVE-2017-17670
Disclosure Date: December 15, 2017 (last updated November 26, 2024)
In VideoLAN VLC media player through 2.2.8, there is a type conversion vulnerability in modules/demux/mp4/libmp4.c in the MP4 demux module leading to a invalid free, because the type of a box may be changed between a read operation and a free operation.
0
Attacker Value
Unknown
CVE-2017-10699
Disclosure Date: June 30, 2017 (last updated November 26, 2024)
avcodec 2.2.x, as used in VideoLAN VLC media player 2.2.7-x before 2017-06-29, allows out-of-bounds heap memory write due to calling memcpy() with a wrong size, leading to a denial of service (application crash) or possibly code execution.
0
Attacker Value
Unknown
CVE-2017-9300
Disclosure Date: May 29, 2017 (last updated November 26, 2024)
plugins\codec\libflac_plugin.dll in VideoLAN VLC media player 2.2.4 allows remote attackers to cause a denial of service (heap corruption and application crash) or possibly have unspecified other impact via a crafted FLAC file.
0
Attacker Value
Unknown
CVE-2017-9301
Disclosure Date: May 29, 2017 (last updated November 26, 2024)
plugins\audio_filter\libmpgatofixed32_plugin.dll in VideoLAN VLC media player 2.2.4 allows remote attackers to cause a denial of service (invalid read and application crash) or possibly have unspecified other impact via a crafted file.
0
Attacker Value
Unknown
CVE-2017-8311
Disclosure Date: May 23, 2017 (last updated November 08, 2023)
Potential heap based buffer overflow in ParseJSS in VideoLAN VLC before 2.2.5 due to skipping NULL terminator in an input string allows attackers to execute arbitrary code via a crafted subtitles file.
0
Attacker Value
Unknown
CVE-2017-8313
Disclosure Date: May 23, 2017 (last updated November 08, 2023)
Heap out-of-bound read in ParseJSS in VideoLAN VLC before 2.2.5 due to missing check of string termination allows attackers to read data beyond allocated memory and potentially crash the process via a crafted subtitles file.
0