Search CVE reports


Toggle filters

11 – 20 of 156 results


CVE-2021-25802

Medium priority
Fixed

A buffer overflow vulnerability in the AVI_ExtractSubtitle component of VideoLAN VLC Media Player 3.0.11 allows attackers to cause an out-of-bounds read via a crafted .avi file.

1 affected package

vlc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
vlc Not affected Not affected Fixed Fixed
Show less packages

CVE-2021-25801

Medium priority
Fixed

A buffer overflow vulnerability in the __Parse_indx component of VideoLAN VLC Media Player 3.0.11 allows attackers to cause an out-of-bounds read via a crafted .avi file.

1 affected package

vlc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
vlc Not affected Not affected Fixed Fixed
Show less packages

CVE-2020-26664

Medium priority
Needs evaluation

A vulnerability in EbmlTypeDispatcher::send in VideoLAN VLC media player 3.0.11 allows attackers to trigger a heap-based buffer overflow via a crafted .mkv file.

1 affected package

vlc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
vlc Not affected Not affected Not affected Needs evaluation Needs evaluation
Show less packages

CVE-2020-13428

Medium priority

Some fixes available 2 of 3

A heap-based buffer overflow in the hxxx_AnnexB_to_xVC function in modules/packetizer/hxxx_nal.c in VideoLAN VLC media player before 3.0.11 for macOS/iOS allows remote attackers to cause a denial of service (application crash) or...

1 affected package

vlc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
vlc Not affected Not affected Fixed Fixed
Show less packages

CVE-2019-19721

Low priority

Some fixes available 2 of 6

An off-by-one error in the DecodeBlock function in codec/sdl_image.c in VideoLAN VLC media player before 3.0.9 allows remote attackers to cause a denial of service (memory corruption) via a crafted image file. NOTE: this may be...

1 affected package

vlc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
vlc Not affected Not affected Fixed
Show less packages

CVE-2020-6080

Medium priority

Some fixes available 2 of 9

An exploitable denial-of-service vulnerability exists in the resource allocation handling of Videolabs libmicrodns 0.1.0. When encountering errors while parsing mDNS messages, some allocated data is not freed, possibly leading to...

2 affected packages

libmicrodns, vlc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libmicrodns Not in release Not in release Not in release Fixed
vlc Not affected Not affected Not affected Fixed
Show less packages

CVE-2020-6079

Medium priority

Some fixes available 2 of 9

An exploitable denial-of-service vulnerability exists in the resource allocation handling of Videolabs libmicrodns 0.1.0. When encountering errors while parsing mDNS messages, some allocated data is not freed, possibly leading to...

2 affected packages

libmicrodns, vlc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libmicrodns Not in release Not in release Not in release Fixed
vlc Not affected Not affected Not affected Fixed
Show less packages

CVE-2020-6078

Medium priority

Some fixes available 2 of 9

An exploitable denial-of-service vulnerability exists in the message-parsing functionality of Videolabs libmicrodns 0.1.0. When parsing mDNS messages in mdns_recv, the return value of the mdns_read_header function is not checked,...

2 affected packages

libmicrodns, vlc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libmicrodns Not in release Not in release Not in release Fixed
vlc Not affected Not affected Not affected Fixed
Show less packages

CVE-2020-6077

Medium priority

Some fixes available 1 of 8

An exploitable denial-of-service vulnerability exists in the message-parsing functionality of Videolabs libmicrodns 0.1.0. When parsing mDNS messages, the implementation does not properly keep track of the available data in the...

2 affected packages

libmicrodns, vlc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libmicrodns Not in release Not in release Not in release Fixed
vlc Not affected Not affected Not affected Not affected
Show less packages

CVE-2020-6073

Medium priority

Some fixes available 2 of 9

An exploitable denial-of-service vulnerability exists in the TXT record-parsing functionality of Videolabs libmicrodns 0.1.0. When parsing the RDATA section in a TXT record in mDNS messages, multiple integer overflows can be...

2 affected packages

libmicrodns, vlc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libmicrodns Not in release Not in release Not in release Fixed
vlc Not affected Not affected Not affected Fixed
Show less packages