Vulnerabilities > Videolan > VLC Media Player > 0.8.2

DATE CVE VULNERABILITY TITLE RISK
2008-02-26 CVE-2008-0984 Resource Management Errors vulnerability in multiple products
The MP4 demuxer (mp4.c) for VLC media player 0.8.6d and earlier, as used in Miro Player 1.1 and earlier, allows remote attackers to overwrite arbitrary memory and execute arbitrary code via a malformed MP4 file.
network
miro videolan CWE-399
critical
9.3
2008-01-16 CVE-2008-0296 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Videolan VLC Media Player
Heap-based buffer overflow in the libaccess_realrtsp plugin in VideoLAN VLC Media Player 0.8.6d and earlier on Windows might allow remote RTSP servers to cause a denial of service (application crash) or execute arbitrary code via a long string.
network
low complexity
microsoft videolan CWE-119
critical
10.0
2008-01-16 CVE-2008-0295 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Videolan VLC Media Player
Heap-based buffer overflow in modules/access/rtsp/real_sdpplin.c in the Xine library, as used in VideoLAN VLC Media Player 0.8.6d and earlier, allows user-assisted remote attackers to cause a denial of service (crash) or execute arbitrary code via long Session Description Protocol (SDP) data.
network
videolan CWE-119
8.5
2007-06-27 CVE-2007-3468 Denial-Of-Service vulnerability in VLC media player
input.c in VideoLAN VLC Media Player before 0.8.6c allows remote attackers to cause a denial of service (crash) via a crafted WAV file that causes an uninitialized i_nb_resamplers variable to be used.
network
low complexity
videolan
7.8
2007-06-27 CVE-2007-3467 Denial-Of-Service vulnerability in VLC media player
Integer overflow in the __status_Update function in stats.c VideoLAN VLC Media Player before 0.8.6c allows remote attackers to cause a denial of service (crash) via a WAV file with a large sample rate.
network
low complexity
videolan
7.8
2007-01-03 CVE-2007-0017 USE of Externally-Controlled Format String vulnerability in Videolan VLC Media Player
Multiple format string vulnerabilities in (1) the cdio_log_handler function in modules/access/cdda/access.c in the CDDA (libcdda_plugin) plugin, and the (2) cdio_log_handler and (3) vcd_log_handler functions in modules/access/vcdx/access.c in the VCDX (libvcdx_plugin) plugin, in VideoLAN VLC 0.7.0 through 0.8.6 allow user-assisted remote attackers to execute arbitrary code via format string specifiers in an invalid URI, as demonstrated by a udp://-- URI in an M3U file.
network
videolan CWE-134
6.8