Vulnerability index

Browse CVEs

91 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Vlc Media Player HIGH 7.8
CVE-2023-46814

A binary hijacking vulnerability exists within the VideoLAN VLC media player before 3.0.19 on Windows. The uninstaller attempts to execute code with …

Fix: 3.0.19+
Fix from $1,950 2023-11-22
Vlc Media Player CRITICAL 9.8
CVE-2023-47359

Videolan VLC prior to version 3.0.20 contains an incorrect offset read that leads to a Heap-Based Buffer Overflow in function GetPacket() and results…

Fix: 3.0.20+
Fix from $2,300 2023-11-07
Vlc Media Player HIGH 7.5
CVE-2023-47360

Videolan VLC prior to version 3.0.20 contains an Integer underflow that leads to an incorrect packet length.

Fix: 3.0.20+
Fix from $1,950 2023-11-07
Vlc Media Player HIGH 7.5
CVE-2021-25804

A NULL-pointer dereference in "Open" in avi.c of VideoLAN VLC Media Player 3.0.11 can a denial of service (DOS) in the application.

Mitigation only
Fix from $1,950 2021-07-26
Vlc Media Player HIGH 7.1
CVE-2021-25801

A buffer overflow vulnerability in the __Parse_indx component of VideoLAN VLC Media Player 3.0.11 allows attackers to cause an out-of-bounds read via…

Mitigation only
Fix from $1,950 2021-07-26
Vlc Media Player HIGH 7.1
CVE-2021-25802

A buffer overflow vulnerability in the AVI_ExtractSubtitle component of VideoLAN VLC Media Player 3.0.11 allows attackers to cause an out-of-bounds r…

Patch available
Fix from $1,950 2021-07-26
Vlc Media Player HIGH 7.1
CVE-2021-25803

A buffer overflow vulnerability in the vlc_input_attachment_New component of VideoLAN VLC Media Player 3.0.11 allows attackers to cause an out-of-bou…

Mitigation only
Fix from $1,950 2021-07-26
Vlc Media Player HIGH 7.8
CVE-2019-19721

An off-by-one error in the DecodeBlock function in codec/sdl_image.c in VideoLAN VLC media player before 3.0.9 allows remote attackers to cause a den…

Fix: 3.0.9+
Fix from $1,950 2020-05-15
Vlc Media Player MEDIUM 5.3
CVE-2013-3564

The web interface in VideoLAN VLC media player before 2.0.7 has no access control which allows remote attackers to view directory listings via the 'd…

Fix: 2.0.7+
Fix from $1,600 2020-02-06
Vlc Media Player MEDIUM 6.1
CVE-2013-3565

Multiple cross-site scripting (XSS) vulnerabilities in the HTTP Interface in VideoLAN VLC Media Player before 2.0.7 allow remote attackers to inject …

Fix: 2.0.7+
Fix from $1,600 2020-01-31
Vlc Media Player HIGH 7.8
CVE-2014-9625

The GetUpdateFile function in misc/update.c in the Updater in VideoLAN VLC media player before 2.1.6 performs an incorrect cast operation from a 64-b…

Fix: 2.1.6+
Fix from $1,950 2020-01-24
Vlc Media Player HIGH 7.8
CVE-2014-9626

Integer underflow in the MP4_ReadBox_String function in modules/demux/mp4/libmp4.c in VideoLAN VLC media player before 2.1.6 allows remote attackers …

Fix: 2.1.6+
Fix from $1,950 2020-01-24
Vlc Media Player HIGH 7.8
CVE-2014-9627

The MP4_ReadBox_String function in modules/demux/mp4/libmp4.c in VideoLAN VLC media player before 2.1.6 performs an incorrect cast operation from a 6…

Fix: 2.1.6+
Fix from $1,950 2020-01-24
Vlc Media Player HIGH 7.8
CVE-2014-9628

The MP4_ReadBox_String function in modules/demux/mp4/libmp4.c in VideoLAN VLC media player before 2.1.6 allows remote attackers to trigger an uninten…

Fix: 2.1.6+
Fix from $1,950 2020-01-24
Vlc Media Player HIGH 7.8
CVE-2014-9629

Integer overflow in the Encode function in modules/codec/schroedinger.c in VideoLAN VLC media player before 2.1.6 and 2.2.x before 2.2.1 allows remot…

Fix: 2.1.6 / 2.2.1+
Fix from $1,950 2020-01-24
Vlc Media Player HIGH 7.8
CVE-2014-9630

The rtp_packetize_xiph_config function in modules/stream_out/rtpfmt.c in VideoLAN VLC media player before 2.1.6 uses a stack-allocation approach with…

Fix: 2.1.6+
Fix from $1,950 2020-01-24
Vlc Media Player HIGH 7.8
CVE-2019-18278

When executing VideoLAN VLC media player 3.0.8 with libqt on Windows, Data from a Faulting Address controls Code Flow starting at libqt_plugin!vlc_en…

No fix yet
Fix from $1,950 2019-10-23
Vlc Media Player HIGH 7.1
CVE-2019-5459

An Integer underflow in VLC Media Player versions < 3.0.7 leads to an out-of-band read.

Fix: 3.0.7+
Fix from $1,950 2019-07-30
Vlc Media Player MEDIUM 5.5
CVE-2019-5460

Double Free in VLC versions <= 3.0.6 leads to a crash.

Fix: after 3.0.6
Fix from $1,600 2019-07-30
Vlc Media Player MEDIUM 5.5
CVE-2019-13615

libebml before 1.3.6, as used in the MKV module in VideoLAN VLC Media Player binaries before 3.0.3, has a heap-based buffer over-read in EbmlElement:…

Fix: 3.0.3+
Fix from $1,600 2019-07-16
Vlc Media Player CRITICAL 9.8
CVE-2019-12874

An issue was discovered in zlib_decompress_extra in modules/demux/mkv/util.cpp in VideoLAN VLC media player 3.x through 3.0.7. The Matroska demuxer, …

Fix: after 3.0.7
Fix from $2,300 2019-06-18
Vlc Media Player MEDIUM 6.5
CVE-2019-5439EPSS 5%

A Buffer Overflow in VLC Media Player < 3.0.7 causes a crash which can possibly be further developed into a remote code execution exploit.

Fix: 3.0.7+
Fix from $1,600 2019-06-13
Vlc For Mobile MEDIUM 6.6
CVE-2018-19937

A local, authenticated attacker can bypass the passcode in the VideoLAN VLC media player app before 3.1.5 for iOS by opening a URL and turning the ph…

Fix: 3.1.5+
Fix from $1,600 2018-12-31
Vlc Media Player HIGH 8.8
CVE-2018-11516

The vlc_demux_chained_Delete function in input/demux_chained.c in VideoLAN VLC media player 3.0.1 allows remote attackers to cause a denial of servic…

No fix yet
Fix from $1,950 2018-05-28
Vlc Media Player CRITICAL 9.8
CVE-2017-10699

avcodec 2.2.x, as used in VideoLAN VLC media player 2.2.7-x before 2017-06-29, allows out-of-bounds heap memory write due to calling memcpy() with a …

Mitigation only
Fix from $2,300 2017-06-30
Vlc Media Player HIGH 7.8
CVE-2017-9300

plugins\codec\libflac_plugin.dll in VideoLAN VLC media player 2.2.4 allows remote attackers to cause a denial of service (heap corruption and applica…

Fix: after 2.2.4
Fix from $1,950 2017-05-29
Vlc Media Player HIGH 7.8
CVE-2017-9301

plugins\audio_filter\libmpgatofixed32_plugin.dll in VideoLAN VLC media player 2.2.4 allows remote attackers to cause a denial of service (invalid rea…

Fix: after 2.2.4
Fix from $1,950 2017-05-29
Vlc Media Player HIGH 7.8
CVE-2017-8311EPSS 9%

Potential heap based buffer overflow in ParseJSS in VideoLAN VLC before 2.2.5 due to skipping NULL terminator in an input string allows attackers to …

Fix: after 2.2.4
Fix from $1,950 2017-05-23
Vlc Media Player MEDIUM 5.5
CVE-2017-8310

Heap out-of-bound read in CreateHtmlSubtitle in VideoLAN VLC 2.2.x due to missing check of string termination allows attackers to read data beyond al…

Mitigation only
Fix from $1,600 2017-05-23
Vlc Media Player MEDIUM 5.5
CVE-2017-8313

Heap out-of-bound read in ParseJSS in VideoLAN VLC before 2.2.5 due to missing check of string termination allows attackers to read data beyond alloc…

Fix: after 2.2.4
Fix from $1,600 2017-05-23