Search CVE reports


Toggle filters

81 – 90 of 157 results


CVE-2017-8310

Medium priority

Some fixes available 3 of 4

Heap out-of-bound read in CreateHtmlSubtitle in VideoLAN VLC 2.2.x due to missing check of string termination allows attackers to read data beyond allocated memory and potentially crash the process (causing a denial of service)...

1 affected package

vlc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
vlc — — — — —
Show less packages

CVE-2014-6440

Medium priority

Some fixes available 1 of 3

VideoLAN VLC media player before 2.1.5 allows remote attackers to execute arbitrary code or cause a denial of service.

1 affected package

vlc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
vlc — — — — —
Show less packages

CVE-2016-5637

Medium priority
Needs evaluation

The restore_tqb_pixels function in libbpg 0.9.5 through 0.9.7 mishandles the transquant_bypass_enable_flag value, which allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds write) via a...

5 affected packages

gst-libav1.0, chromium-browser, ffmpeg, oxide-qt, vlc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gst-libav1.0 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
chromium-browser Not affected Not affected Not affected Not in release Not affected
ffmpeg Not affected Not affected Not affected Not affected Not affected
oxide-qt Not in release Not in release Not in release Not in release Not in release
vlc Not affected Not affected Not affected Not affected Not affected
Show less packages

CVE-2016-5108

Medium priority

Some fixes available 2 of 5

Buffer overflow in the DecodeAdpcmImaQT function in modules/codec/adpcm.c in VideoLAN VLC media player before 2.2.4 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted...

1 affected package

vlc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
vlc — — — — —
Show less packages

CVE-2016-3941

Medium priority

Some fixes available 1 of 2

Buffer overflow in the AStreamPeekStream function in input/stream.c in VideoLAN VLC media player before 2.2.0 allows remote attackers to cause a denial of service (crash) via a crafted wav file, related to "seek across EOF."

1 affected package

vlc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
vlc — — — — —
Show less packages

CVE-2015-5949

Medium priority
Ignored

VideoLAN VLC media player 2.2.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted 3GP file, which triggers the freeing of arbitrary pointers.

1 affected package

vlc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
vlc — — — — —
Show less packages

CVE-2014-9743

Medium priority

Some fixes available 1 of 2

Cross-site scripting (XSS) vulnerability in the httpd_HtmlError function in network/httpd.c in the web interface in VideoLAN VLC Media Player before 2.2.0 allows remote attackers to inject arbitrary web script or HTML via the path info.

1 affected package

vlc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
vlc — — — — —
Show less packages

CVE-2014-9598

Medium priority
Ignored

The picture_Release function in misc/picture.c in VideoLAN VLC media player 2.1.5 allows remote attackers to execute arbitrary code or cause a denial of service (write access violation) via a crafted M2V file.

1 affected package

vlc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
vlc — — — — —
Show less packages

CVE-2014-9597

Medium priority

Some fixes available 1 of 2

The picture_pool_Delete function in misc/picture_pool.c in VideoLAN VLC media player 2.1.5 allows remote attackers to execute arbitrary code or cause a denial of service (DEP violation and application crash) via a crafted FLV file.

1 affected package

vlc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
vlc — — — — —
Show less packages

CVE-2011-3623

Medium priority
Ignored

Multiple stack-based buffer overflows in VideoLAN VLC media player before 1.0.2 allow remote attackers to execute arbitrary code via (1) a crafted ASF file, related to the ASF_ObjectDumpDebug function...

1 affected package

vlc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
vlc — — — — —
Show less packages