CVE-2020-13428 is a heap-based buffer overflow vulnerability in VideoLAN VLC media player versions prior to 3.0.11 for macOS/iOS. This flaw allows remote attackers to trigger a denial of service or execute arbitrary code by enticing a user to open a specially crafted H.264 Annex-B video file. With a CVSS score of 7.8 (High), the vulnerability has a low attack complexity and requires user interaction, but can lead to full compromise of confidentiality, integrity, and availability. While not currently listed on the KEV catalog or having public exploit code in Metasploit or ExploitDB, it has received media attention and community discussion, indicating awareness of its potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.0.11CPE matchmatch criteria | cpe:2.3:a:videolan:vlc_media_player:*:*:*:*:*:iphone_os:*:* | ||
< 3.0.11CPE matchmatch criteria | cpe:2.3:a:videolan:vlc_media_player:*:*:*:*:*:macos:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.