Filtered by vendor Videolan
Subscribe
Total
125 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2011-1931 | 3 Ffmpeg, Libav, Videolan | 4 Ffmpeg, Libavcodec, Libav and 1 more | 2024-02-04 | 6.8 MEDIUM | N/A |
sp5xdec.c in the Sunplus SP5X JPEG decoder in libavcodec in FFmpeg before 0.6.3 and libav through 0.6.2, as used in VideoLAN VLC media player 1.1.9 and earlier and other products, performs a write operation outside the bounds of an unspecified array, which allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a malformed AMV file. | |||||
CVE-2010-3276 | 1 Videolan | 1 Vlc Media Player | 2024-02-04 | 9.3 HIGH | N/A |
libdirectx_plugin.dll in VideoLAN VLC Media Player before 1.1.8 allows remote attackers to execute arbitrary code via a crafted width in an NSV file. | |||||
CVE-2012-1775 | 1 Videolan | 1 Vlc Media Player | 2024-02-04 | 9.3 HIGH | N/A |
Stack-based buffer overflow in VideoLAN VLC media player before 2.0.1 allows remote attackers to execute arbitrary code via a crafted MMS:// stream. | |||||
CVE-2011-2194 | 1 Videolan | 1 Vlc Media Player | 2024-02-04 | 9.3 HIGH | N/A |
Integer overflow in the XSPF playlist parser in VideoLAN VLC media player 0.8.5 through 1.1.9 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors that trigger a heap-based buffer overflow. | |||||
CVE-2011-0531 | 1 Videolan | 1 Vlc Media Player | 2024-02-04 | 9.3 HIGH | N/A |
demux/mkv/mkv.hpp in the MKV demuxer plugin in VideoLAN VLC media player 1.1.6.1 and earlier allows remote attackers to cause a denial of service (crash) and execute arbitrary commands via a crafted MKV (WebM or Matroska) file that triggers memory corruption, related to "class mismatching" and the MKV_IS_ID macro. | |||||
CVE-2010-0364 | 1 Videolan | 1 Vlc Media Player | 2024-02-04 | 9.3 HIGH | N/A |
Stack-based buffer overflow in VideoLAN VLC Media Player 0.8.6 allows user-assisted remote attackers to execute arbitrary code via an ogg file with a crafted Advanced SubStation Alpha Subtitle (.ass) file, probably involving the Dialogue field. | |||||
CVE-2011-2588 | 1 Videolan | 1 Vlc Media Player | 2024-02-04 | 6.8 MEDIUM | N/A |
Heap-based buffer overflow in the AVI_ChunkRead_strf function in libavi.c in the AVI demuxer in VideoLAN VLC media player before 1.1.11 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted AVI media file. | |||||
CVE-2010-2937 | 1 Videolan | 1 Vlc Media Player | 2024-02-04 | 5.0 MEDIUM | N/A |
The ReadMetaFromId3v2 function in taglib.cpp in the TagLib plugin in VideoLAN VLC media player 0.9.0 through 1.1.2 does not properly process ID3v2 tags, which allows remote attackers to cause a denial of service (application crash) via a crafted media file. | |||||
CVE-2011-0522 | 1 Videolan | 1 Vlc Media Player | 2024-02-04 | 6.8 MEDIUM | N/A |
The StripTags function in (1) the USF decoder (modules/codec/subtitles/subsdec.c) and (2) the Text decoder (modules/codec/subtitles/subsusf.c) in VideoLAN VLC Media Player 1.1 before 1.1.6-rc allows remote attackers to execute arbitrary code via a subtitle with an opening "<" without a closing ">" in an MKV file, which triggers heap memory corruption, as demonstrated using refined-australia-blu720p-sample.mkv. | |||||
CVE-2012-0904 | 1 Videolan | 1 Vlc Media Player | 2024-02-04 | 4.3 MEDIUM | N/A |
VLC media player 1.1.11 allows remote attackers to cause a denial of service (crash) via a long string in an amr file. | |||||
CVE-2010-3275 | 1 Videolan | 1 Vlc Media Player | 2024-02-04 | 9.3 HIGH | N/A |
libdirectx_plugin.dll in VideoLAN VLC Media Player before 1.1.8 allows remote attackers to execute arbitrary code via a crafted width in an AMV file, related to a "dangling pointer vulnerability." | |||||
CVE-2011-1684 | 1 Videolan | 1 Vlc Media Player | 2024-02-04 | 6.8 MEDIUM | N/A |
Heap-based buffer overflow in the MP4_ReadBox_skcr function in libmp4.c in the MP4 demultiplexer in VideoLAN VLC media player 1.x before 1.1.9 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted MP4 file. | |||||
CVE-2010-3907 | 1 Videolan | 1 Vlc Media Player | 2024-02-04 | 9.3 HIGH | N/A |
Multiple integer overflows in real.c in the Real demuxer plugin in VideoLAN VLC Media Player before 1.1.6 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a zero i_subpackets value in a Real Media file, leading to a heap-based buffer overflow. | |||||
CVE-2010-3124 | 1 Videolan | 1 Vlc Media Player | 2024-02-04 | 9.3 HIGH | N/A |
Untrusted search path vulnerability in bin/winvlc.c in VLC Media Player 1.1.3 and earlier allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse wintab32.dll that is located in the same folder as a .mp3 file. | |||||
CVE-2011-1087 | 1 Videolan | 1 Vlc Media Player | 2024-02-04 | 7.6 HIGH | N/A |
Buffer overflow in VideoLAN VLC media player 1.0.5 allows user-assisted remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted .mp3 file that is played during bookmark creation. | |||||
CVE-2011-0021 | 1 Videolan | 1 Vlc Media Player | 2024-02-04 | 9.3 HIGH | N/A |
Multiple heap-based buffer overflows in cdg.c in the CDG decoder in VideoLAN VLC Media Player before 1.1.6 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted CDG video. | |||||
CVE-2008-4558 | 1 Videolan | 1 Vlc Media Player | 2024-02-04 | 6.8 MEDIUM | N/A |
Array index error in VLC media player 0.9.2 allows remote attackers to overwrite arbitrary memory and execute arbitrary code via an XSPF playlist file with a negative identifier tag, which passes a signed comparison. | |||||
CVE-2008-4654 | 1 Videolan | 1 Vlc Media Player | 2024-02-04 | 9.3 HIGH | N/A |
Stack-based buffer overflow in the parse_master function in the Ty demux plugin (modules/demux/ty.c) in VLC Media Player 0.9.0 through 0.9.4 allows remote attackers to execute arbitrary code via a TiVo TY media file with a header containing a crafted size value. | |||||
CVE-2008-1768 | 1 Videolan | 1 Vlc | 2024-02-04 | 6.8 MEDIUM | N/A |
Multiple integer overflows in VLC before 0.8.6f allow remote attackers to cause a denial of service (crash) via the (1) MP4 demuxer, (2) Real demuxer, and (3) Cinepak codec, which triggers a buffer overflow. | |||||
CVE-2009-2484 | 2 Microsoft, Videolan | 2 Windows, Vlc Media Player | 2024-02-04 | 9.3 HIGH | N/A |
Stack-based buffer overflow in the Win32AddConnection function in modules/access/smb.c in VideoLAN VLC media player 0.9.9, when running on Microsoft Windows, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long smb URI in a playlist file. |