Show filters
113 Total Results
Displaying 61-70 of 113
Sort by:
Attacker Value
Unknown
CVE-2010-2062
Disclosure Date: December 26, 2014 (last updated October 05, 2023)
Integer underflow in the real_get_rdt_chunk function in real.c, as used in modules/access/rtsp/real.c in VideoLAN VLC media player before 1.0.1 and stream/realrtsp/real.c in MPlayer before r29447, allows remote attackers to execute arbitrary code via a crafted length value in an RDT chunk header.
0
Attacker Value
Unknown
CVE-2014-3441
Disclosure Date: May 14, 2014 (last updated October 05, 2023)
codec\libpng_plugin.dll in VideoLAN VLC Media Player 2.1.3 allows remote attackers to cause a denial of service (crash) via a crafted .png file, as demonstrated by a png in a .wave file.
0
Attacker Value
Unknown
CVE-2013-7340
Disclosure Date: March 21, 2014 (last updated October 05, 2023)
VideoLAN VLC Media Player before 2.0.7 allows remote attackers to cause a denial of service (memory consumption) via a crafted playlist file.
0
Attacker Value
Unknown
CVE-2014-1684
Disclosure Date: March 03, 2014 (last updated October 05, 2023)
The ASF_ReadObject_file_properties function in modules/demux/asf/libasf.c in the ASF Demuxer in VideoLAN VLC Media Player before 2.1.3 allows remote attackers to cause a denial of service (divide-by-zero error and crash) via a zero minimum and maximum data packet size in an ASF file.
0
Attacker Value
Unknown
CVE-2013-6934
Disclosure Date: January 23, 2014 (last updated October 05, 2023)
The parseRTSPRequestString function in Live Networks Live555 Streaming Media 2013.11.26, as used in VideoLAN VLC Media Player, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a space character at the beginning of an RTSP message, which triggers an integer underflow, infinite loop, and buffer overflow. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-6933.
0
Attacker Value
Unknown
CVE-2013-6283
Disclosure Date: October 25, 2013 (last updated October 05, 2023)
VideoLAN VLC Media Player 2.0.8 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in a URL in a m3u file.
0
Attacker Value
Unknown
CVE-2013-4388
Disclosure Date: October 11, 2013 (last updated October 05, 2023)
Buffer overflow in the mp4a packetizer (modules/packetizer/mpeg4audio.c) in VideoLAN VLC Media Player before 2.0.8 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors.
0
Attacker Value
Unknown
CVE-2013-1868
Disclosure Date: July 10, 2013 (last updated October 05, 2023)
Multiple buffer overflows in VideoLAN VLC media player 2.0.4 and earlier allow remote attackers to cause a denial of service (crash) and execute arbitrary code via vectors related to the (1) freetype renderer and (2) HTML subtitle parser.
0
Attacker Value
Unknown
CVE-2012-5855
Disclosure Date: July 10, 2013 (last updated October 05, 2023)
The SHAddToRecentDocs function in VideoLAN VLC media player 2.0.4 and earlier might allow user-assisted attackers to cause a denial of service (crash) via a crafted file name that triggers an incorrect string-length calculation when the file is added to VLC. NOTE: it is not clear whether this issue crosses privilege boundaries or whether it can be exploited without user interaction.
0
Attacker Value
Unknown
CVE-2013-1954
Disclosure Date: July 10, 2013 (last updated October 05, 2023)
The ASF Demuxer (modules/demux/asf/asf.c) in VideoLAN VLC media player 2.0.5 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted ASF movie that triggers an out-of-bounds read.
0