CVE-2014-1684 describes a denial-of-service vulnerability in VideoLAN VLC Media Player versions prior to 2.1.3. This flaw, located in the ASF Demuxer's ASF_ReadObject_file_properties function, allows remote attackers to crash the application via a specially crafted ASF file containing a zero minimum and maximum data packet size, leading to a divide-by-zero error. The vulnerability has a CVSS score of 4.3, indicating a medium severity. It can be exploited remotely with medium attack complexity, requiring user interaction (e.g., opening a malicious file), and results in a denial of service (application crash) without impacting confidentiality or integrity. While not actively exploited in the wild and not listed in CISA's KEV catalog, a proof-of-concept exploit (EDB-31429) is publicly available on ExploitDB. There is minimal community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.1.2CPE matchmatch criteria | cpe:2.3:a:videolan:vlc_media_player:*:*:*:*:*:*:*:* | ||
1.0.0CPE matchmatch criteria | cpe:2.3:a:videolan:vlc_media_player:1.0.0:*:*:*:*:*:*:* | ||
1.0.1CPE matchmatch criteria | cpe:2.3:a:videolan:vlc_media_player:1.0.1:*:*:*:*:*:*:* | ||
1.0.2CPE matchmatch criteria | cpe:2.3:a:videolan:vlc_media_player:1.0.2:*:*:*:*:*:*:* | ||
1.0.3CPE matchmatch criteria | cpe:2.3:a:videolan:vlc_media_player:1.0.3:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.