Vulnerabilities > Videolan > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2019-08-29 | CVE-2019-14535 | Divide By Zero vulnerability in multiple products A divide-by-zero error exists in the SeekIndex function of demux/asf/asf.c in VideoLAN VLC media player 3.0.7.1. | 6.8 |
2019-08-29 | CVE-2019-14498 | Divide By Zero vulnerability in multiple products A divide-by-zero error exists in the Control function of demux/caf.c in VideoLAN VLC media player 3.0.7.1. | 6.8 |
2019-08-29 | CVE-2019-14438 | Out-of-bounds Read vulnerability in multiple products A heap-based buffer over-read in xiph_PackHeaders() in modules/demux/xiph.h in VideoLAN VLC media player 3.0.7.1 allows remote attackers to trigger a heap-based buffer over-read via a crafted .ogg file. | 6.8 |
2019-08-29 | CVE-2019-14437 | Out-of-bounds Read vulnerability in multiple products The xiph_SplitHeaders function in modules/demux/xiph.h in VideoLAN VLC media player 3.0.7.1 does not check array bounds properly. | 6.8 |
2019-07-30 | CVE-2019-5460 | Double Free vulnerability in multiple products Double Free in VLC versions <= 3.0.6 leads to a crash. | 5.5 |
2019-07-30 | CVE-2019-5459 | Integer Underflow (Wrap or Wraparound) vulnerability in multiple products An Integer underflow in VLC Media Player versions < 3.0.7 leads to an out-of-band read. | 5.8 |
2019-07-16 | CVE-2019-13615 | Out-of-bounds Read vulnerability in Videolan VLC Media Player libebml before 1.3.6, as used in the MKV module in VideoLAN VLC Media Player binaries before 3.0.3, has a heap-based buffer over-read in EbmlElement::FindNextElement. | 4.3 |
2019-06-13 | CVE-2019-5439 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Videolan VLC Media Player A Buffer Overflow in VLC Media Player < 3.0.7 causes a crash which can possibly be further developed into a remote code execution exploit. | 4.3 |
2018-12-31 | CVE-2018-19937 | Improper Authentication vulnerability in Videolan VLC FOR Mobile A local, authenticated attacker can bypass the passcode in the VideoLAN VLC media player app before 3.1.5 for iOS by opening a URL and turning the phone. | 4.6 |
2018-07-11 | CVE-2018-11529 | Use After Free vulnerability in multiple products VideoLAN VLC media player 2.2.x is prone to a use after free vulnerability which an attacker can leverage to execute arbitrary code via crafted MKV files. | 6.8 |