Show filters
113 Total Results
Displaying 71-80 of 113
Sort by:
Attacker Value
Unknown

CVE-2013-3245

Disclosure Date: July 10, 2013 (last updated November 08, 2023)
plugins/demux/libmkv_plugin.dll in VideoLAN VLC Media Player 2.0.7, and possibly other versions, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted MKV file, possibly involving an integer overflow and out-of-bounds read or heap-based buffer overflow, or an uncaught exception. NOTE: the vendor disputes the severity and claimed vulnerability type of this issue, stating "This PoC crashes VLC, indeed, but does nothing more... this is not an integer overflow error, but an uncaught exception and I doubt that it is exploitable. This uncaught exception makes VLC abort, not execute random code, on my Linux 64bits machine." A PoC posted by the original researcher shows signs of an attacker-controlled out-of-bounds read, but the affected instruction does not involve a register that directly influences control flow
0
Attacker Value
Unknown

CVE-2012-0023

Disclosure Date: October 30, 2012 (last updated October 05, 2023)
Double free vulnerability in the get_chunk_header function in modules/demux/ty.c in VideoLAN VLC media player 0.9.0 through 1.1.12 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TiVo (TY) file.
0
Attacker Value
Unknown

CVE-2012-5470

Disclosure Date: October 26, 2012 (last updated October 05, 2023)
libpng_plugin in VideoLAN VLC media player 2.0.3 allows remote attackers to cause a denial of service (application crash) via a crafted PNG file.
0
Attacker Value
Unknown

CVE-2012-3377

Disclosure Date: July 12, 2012 (last updated October 04, 2023)
Heap-based buffer overflow in the Ogg_DecodePacket function in the OGG demuxer (modules/demux/ogg.c) in VideoLAN VLC media player before 2.0.2 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted OGG file.
0
Attacker Value
Unknown

CVE-2012-2396

Disclosure Date: April 19, 2012 (last updated October 04, 2023)
VideoLAN VLC media player 2.0.1 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted MP4 file.
0
Attacker Value
Unknown

CVE-2012-1776

Disclosure Date: March 19, 2012 (last updated October 04, 2023)
Multiple heap-based buffer overflows in VideoLAN VLC media player before 2.0.1 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted Real RTSP stream.
0
Attacker Value
Unknown

CVE-2012-1775

Disclosure Date: March 19, 2012 (last updated October 04, 2023)
Stack-based buffer overflow in VideoLAN VLC media player before 2.0.1 allows remote attackers to execute arbitrary code via a crafted MMS:// stream.
0
Attacker Value
Unknown

CVE-2012-0904

Disclosure Date: January 20, 2012 (last updated October 04, 2023)
VLC media player 1.1.11 allows remote attackers to cause a denial of service (crash) via a long string in an amr file.
0
Attacker Value
Unknown

CVE-2011-2587

Disclosure Date: July 27, 2011 (last updated October 04, 2023)
Heap-based buffer overflow in the DemuxAudioSipr function in real.c in the RealMedia demuxer in VideoLAN VLC media player 1.1.x before 1.1.11 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted Real Media file.
0
Attacker Value
Unknown

CVE-2011-2588

Disclosure Date: July 27, 2011 (last updated October 04, 2023)
Heap-based buffer overflow in the AVI_ChunkRead_strf function in libavi.c in the AVI demuxer in VideoLAN VLC media player before 1.1.11 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted AVI media file.
0