CVE-2007-6262 describes a critical vulnerability in the axvlc.dll ActiveX control within VideoLAN VLC Media Player versions prior to 0.8.6d. This flaw, stemming from a "bad initialized pointer" or "recursive plugin release," allows remote attackers to execute arbitrary code by supplying crafted arguments to the addTarget, getVariable, or setVariable functions. With a CVSS score of 6.8 and a FAUCET Risk Score of 96/100, this vulnerability presents a significant risk, enabling potential compromise of confidentiality, integrity, and availability. While not listed on the KEV catalog or Hot List, an ExploitDB entry (EDB-4688) confirms the existence of public exploit code, despite a lack of broader community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.8.6CPE matchmatch criteria | cpe:2.3:a:videolan:vlc_media_player:0.8.6:*:*:*:*:*:*:* | ||
0.8.6aCPE matchmatch criteria | cpe:2.3:a:videolan:vlc_media_player:0.8.6a:*:*:*:*:*:*:* | ||
0.8.6bCPE matchmatch criteria | cpe:2.3:a:videolan:vlc_media_player:0.8.6b:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.