Show filters
127 Total Results
Displaying 1-10 of 127
Sort by:
Attacker Value
Unknown

VLC zlib_decompress_extra Double Free Vulnerability

Disclosure Date: June 18, 2019 (last updated October 06, 2023)
An issue was discovered in zlib_decompress_extra in modules/demux/mkv/util.cpp in VideoLAN VLC media player 3.x through 3.0.7. The Matroska demuxer, while parsing a malformed MKV file type, has a double free.
0
Attacker Value
Unknown

CVE-2024-1580

Disclosure Date: February 19, 2024 (last updated February 14, 2025)
An integer overflow in dav1d AV1 decoder that can occur when decoding videos with large frame size. This can lead to memory corruption within the AV1 decoder. We recommend upgrading past version 1.4.0 of dav1d.
Attacker Value
Unknown

CVE-2023-46814

Disclosure Date: November 22, 2023 (last updated November 30, 2023)
A binary hijacking vulnerability exists within the VideoLAN VLC media player before 3.0.19 on Windows. The uninstaller attempts to execute code with elevated privileges out of a standard user writable location. Standard users may use this to gain arbitrary code execution as SYSTEM.
Attacker Value
Unknown

CVE-2023-47360

Disclosure Date: November 07, 2023 (last updated November 14, 2023)
Videolan VLC prior to version 3.0.20 contains an Integer underflow that leads to an incorrect packet length.
Attacker Value
Unknown

CVE-2023-47359

Disclosure Date: November 07, 2023 (last updated November 14, 2023)
Videolan VLC prior to version 3.0.20 contains an incorrect offset read that leads to a Heap-Based Buffer Overflow in function GetPacket() and results in a memory corruption.
Attacker Value
Unknown

CVE-2023-32570

Disclosure Date: May 10, 2023 (last updated November 02, 2023)
VideoLAN dav1d before 1.2.0 has a thread_task.c race condition that can lead to an application crash, related to dav1d_decode_frame_exit.
Attacker Value
Unknown

CVE-2022-41325

Disclosure Date: December 06, 2022 (last updated October 08, 2023)
An integer overflow in the VNC module in VideoLAN VLC Media Player through 3.0.17.4 allows attackers, by tricking a user into opening a crafted playlist or connecting to a rogue VNC server, to crash VLC or execute code under some conditions.
Attacker Value
Unknown

CVE-2021-25804

Disclosure Date: July 26, 2021 (last updated November 28, 2024)
A NULL-pointer dereference in "Open" in avi.c of VideoLAN VLC Media Player 3.0.11 can a denial of service (DOS) in the application.
Attacker Value
Unknown

CVE-2021-25802

Disclosure Date: July 26, 2021 (last updated November 28, 2024)
A buffer overflow vulnerability in the AVI_ExtractSubtitle component of VideoLAN VLC Media Player 3.0.11 allows attackers to cause an out-of-bounds read via a crafted .avi file.
Attacker Value
Unknown

CVE-2021-25801

Disclosure Date: July 26, 2021 (last updated November 28, 2024)
A buffer overflow vulnerability in the __Parse_indx component of VideoLAN VLC Media Player 3.0.11 allows attackers to cause an out-of-bounds read via a crafted .avi file.