Show filters
127 Total Results
Displaying 51-60 of 127
Sort by:
Attacker Value
Unknown
CVE-2017-8312
Disclosure Date: May 23, 2017 (last updated November 08, 2023)
Heap out-of-bound read in ParseJSS in VideoLAN VLC due to missing check of string length allows attackers to read heap uninitialized data via a crafted subtitles file.
0
Attacker Value
Unknown
CVE-2017-8310
Disclosure Date: May 23, 2017 (last updated November 08, 2023)
Heap out-of-bound read in CreateHtmlSubtitle in VideoLAN VLC 2.2.x due to missing check of string termination allows attackers to read data beyond allocated memory and potentially crash the process (causing a denial of service) via a crafted subtitles file.
0
Attacker Value
Unknown
CVE-2014-6440
Disclosure Date: March 28, 2017 (last updated November 26, 2024)
VideoLAN VLC media player before 2.1.5 allows remote attackers to execute arbitrary code or cause a denial of service.
0
Attacker Value
Unknown
CVE-2016-5108
Disclosure Date: June 08, 2016 (last updated November 25, 2024)
Buffer overflow in the DecodeAdpcmImaQT function in modules/codec/adpcm.c in VideoLAN VLC media player before 2.2.4 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted QuickTime IMA file.
0
Attacker Value
Unknown
CVE-2016-3941
Disclosure Date: April 18, 2016 (last updated November 25, 2024)
Buffer overflow in the AStreamPeekStream function in input/stream.c in VideoLAN VLC media player before 2.2.0 allows remote attackers to cause a denial of service (crash) via a crafted wav file, related to "seek across EOF."
0
Attacker Value
Unknown
CVE-2015-5949
Disclosure Date: August 25, 2015 (last updated October 05, 2023)
VideoLAN VLC media player 2.2.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted 3GP file, which triggers the freeing of arbitrary pointers.
0
Attacker Value
Unknown
CVE-2014-9743
Disclosure Date: August 17, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the httpd_HtmlError function in network/httpd.c in the web interface in VideoLAN VLC Media Player before 2.2.0 allows remote attackers to inject arbitrary web script or HTML via the path info.
0
Attacker Value
Unknown
CVE-2014-9597
Disclosure Date: January 21, 2015 (last updated October 05, 2023)
The picture_pool_Delete function in misc/picture_pool.c in VideoLAN VLC media player 2.1.5 allows remote attackers to execute arbitrary code or cause a denial of service (DEP violation and application crash) via a crafted FLV file.
0
Attacker Value
Unknown
CVE-2014-9598
Disclosure Date: January 21, 2015 (last updated October 05, 2023)
The picture_Release function in misc/picture.c in VideoLAN VLC media player 2.1.5 allows remote attackers to execute arbitrary code or cause a denial of service (write access violation) via a crafted M2V file.
0
Attacker Value
Unknown
CVE-2011-3623
Disclosure Date: December 26, 2014 (last updated October 05, 2023)
Multiple stack-based buffer overflows in VideoLAN VLC media player before 1.0.2 allow remote attackers to execute arbitrary code via (1) a crafted ASF file, related to the ASF_ObjectDumpDebug function in modules/demux/asf/libasf.c; (2) a crafted AVI file, related to the AVI_ChunkDumpDebug_level function in modules/demux/avi/libavi.c; or (3) a crafted MP4 file, related to the __MP4_BoxDumpStructure function in modules/demux/mp4/libmp4.c.
0