Search CVE reports


Toggle filters

11 – 20 of 156 results


CVE-2021-25802

Medium priority
Fixed

A buffer overflow vulnerability in the AVI_ExtractSubtitle component of VideoLAN VLC Media Player 3.0.11 allows attackers to cause an out-of-bounds read via a crafted .avi file.

1 affected package

vlc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
vlc — Not affected Not affected Fixed Fixed
Show less packages

CVE-2021-25801

Medium priority
Fixed

A buffer overflow vulnerability in the __Parse_indx component of VideoLAN VLC Media Player 3.0.11 allows attackers to cause an out-of-bounds read via a crafted .avi file.

1 affected package

vlc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
vlc — Not affected Not affected Fixed Fixed
Show less packages

CVE-2020-26664

Medium priority
Needs evaluation

A vulnerability in EbmlTypeDispatcher::send in VideoLAN VLC media player 3.0.11 allows attackers to trigger a heap-based buffer overflow via a crafted .mkv file.

1 affected package

vlc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
vlc Not affected Not affected Not affected Needs evaluation Needs evaluation
Show less packages

CVE-2020-13428

Medium priority

Some fixes available 2 of 3

A heap-based buffer overflow in the hxxx_AnnexB_to_xVC function in modules/packetizer/hxxx_nal.c in VideoLAN VLC media player before 3.0.11 for macOS/iOS allows remote attackers to cause a denial of service (application crash) or...

1 affected package

vlc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
vlc — Not affected Not affected Fixed Fixed
Show less packages

CVE-2019-19721

Low priority

Some fixes available 2 of 6

An off-by-one error in the DecodeBlock function in codec/sdl_image.c in VideoLAN VLC media player before 3.0.9 allows remote attackers to cause a denial of service (memory corruption) via a crafted image file. NOTE: this may be...

1 affected package

vlc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
vlc — — Not affected Not affected Fixed
Show less packages

CVE-2020-6080

Medium priority

Some fixes available 2 of 9

An exploitable denial-of-service vulnerability exists in the resource allocation handling of Videolabs libmicrodns 0.1.0. When encountering errors while parsing mDNS messages, some allocated data is not freed, possibly leading to...

2 affected packages

libmicrodns, vlc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libmicrodns — Not in release Not in release Not in release Fixed
vlc — Not affected Not affected Not affected Fixed
Show less packages

CVE-2020-6079

Medium priority

Some fixes available 2 of 9

An exploitable denial-of-service vulnerability exists in the resource allocation handling of Videolabs libmicrodns 0.1.0. When encountering errors while parsing mDNS messages, some allocated data is not freed, possibly leading to...

2 affected packages

libmicrodns, vlc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libmicrodns — Not in release Not in release Not in release Fixed
vlc — Not affected Not affected Not affected Fixed
Show less packages

CVE-2020-6078

Medium priority

Some fixes available 2 of 9

An exploitable denial-of-service vulnerability exists in the message-parsing functionality of Videolabs libmicrodns 0.1.0. When parsing mDNS messages in mdns_recv, the return value of the mdns_read_header function is not checked,...

2 affected packages

libmicrodns, vlc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libmicrodns — Not in release Not in release Not in release Fixed
vlc — Not affected Not affected Not affected Fixed
Show less packages

CVE-2020-6077

Medium priority

Some fixes available 1 of 8

An exploitable denial-of-service vulnerability exists in the message-parsing functionality of Videolabs libmicrodns 0.1.0. When parsing mDNS messages, the implementation does not properly keep track of the available data in the...

2 affected packages

libmicrodns, vlc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libmicrodns — Not in release Not in release Not in release Fixed
vlc — Not affected Not affected Not affected Not affected
Show less packages

CVE-2020-6073

Medium priority

Some fixes available 2 of 9

An exploitable denial-of-service vulnerability exists in the TXT record-parsing functionality of Videolabs libmicrodns 0.1.0. When parsing the RDATA section in a TXT record in mDNS messages, multiple integer overflows can be...

2 affected packages

libmicrodns, vlc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libmicrodns — Not in release Not in release Not in release Fixed
vlc — Not affected Not affected Not affected Fixed
Show less packages