Show filters
127 Total Results
Displaying 71-80 of 127
Sort by:
Attacker Value
Unknown

CVE-2013-6283

Disclosure Date: October 25, 2013 (last updated October 05, 2023)
VideoLAN VLC Media Player 2.0.8 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in a URL in a m3u file.
0
Attacker Value
Unknown

CVE-2013-4388

Disclosure Date: October 11, 2013 (last updated October 05, 2023)
Buffer overflow in the mp4a packetizer (modules/packetizer/mpeg4audio.c) in VideoLAN VLC Media Player before 2.0.8 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors.
0
Attacker Value
Unknown

CVE-2013-1868

Disclosure Date: July 10, 2013 (last updated October 05, 2023)
Multiple buffer overflows in VideoLAN VLC media player 2.0.4 and earlier allow remote attackers to cause a denial of service (crash) and execute arbitrary code via vectors related to the (1) freetype renderer and (2) HTML subtitle parser.
0
Attacker Value
Unknown

CVE-2012-5855

Disclosure Date: July 10, 2013 (last updated October 05, 2023)
The SHAddToRecentDocs function in VideoLAN VLC media player 2.0.4 and earlier might allow user-assisted attackers to cause a denial of service (crash) via a crafted file name that triggers an incorrect string-length calculation when the file is added to VLC. NOTE: it is not clear whether this issue crosses privilege boundaries or whether it can be exploited without user interaction.
0
Attacker Value
Unknown

CVE-2013-1954

Disclosure Date: July 10, 2013 (last updated October 05, 2023)
The ASF Demuxer (modules/demux/asf/asf.c) in VideoLAN VLC media player 2.0.5 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted ASF movie that triggers an out-of-bounds read.
0
Attacker Value
Unknown

CVE-2013-3245

Disclosure Date: July 10, 2013 (last updated November 08, 2023)
plugins/demux/libmkv_plugin.dll in VideoLAN VLC Media Player 2.0.7, and possibly other versions, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted MKV file, possibly involving an integer overflow and out-of-bounds read or heap-based buffer overflow, or an uncaught exception. NOTE: the vendor disputes the severity and claimed vulnerability type of this issue, stating "This PoC crashes VLC, indeed, but does nothing more... this is not an integer overflow error, but an uncaught exception and I doubt that it is exploitable. This uncaught exception makes VLC abort, not execute random code, on my Linux 64bits machine." A PoC posted by the original researcher shows signs of an attacker-controlled out-of-bounds read, but the affected instruction does not involve a register that directly influences control flow
0
Attacker Value
Unknown

CVE-2012-0023

Disclosure Date: October 30, 2012 (last updated October 05, 2023)
Double free vulnerability in the get_chunk_header function in modules/demux/ty.c in VideoLAN VLC media player 0.9.0 through 1.1.12 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TiVo (TY) file.
0
Attacker Value
Unknown

CVE-2012-5470

Disclosure Date: October 26, 2012 (last updated October 05, 2023)
libpng_plugin in VideoLAN VLC media player 2.0.3 allows remote attackers to cause a denial of service (application crash) via a crafted PNG file.
0
Attacker Value
Unknown

CVE-2012-3377

Disclosure Date: July 12, 2012 (last updated October 04, 2023)
Heap-based buffer overflow in the Ogg_DecodePacket function in the OGG demuxer (modules/demux/ogg.c) in VideoLAN VLC media player before 2.0.2 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted OGG file.
0
Attacker Value
Unknown

CVE-2012-2396

Disclosure Date: April 19, 2012 (last updated October 04, 2023)
VideoLAN VLC media player 2.0.1 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted MP4 file.
0