Videolan maintains a tightly focused portfolio centered on VLC Media Player and related multimedia libraries (including dav1d and libbluray) that achieve exceptionally broad distribution across consumer devices, media centers, and cross-platform endpoints. The vendor's vulnerability profile, despite a narrow product count, reflects the complexity inherent to audio and video codec parsing and memory management: recurring exposures cluster around buffer-boundary violations, out-of-bounds reads and writes, and input-validation weaknesses that are characteristic of media-processing attack surfaces. A meaningful share of Videolan's disclosures reach serious severity, and the vendor's vulnerabilities frequently acquire public exploit code, consistent with the accessibility and popularity of VLC's user-facing attack surface. Defenders should treat VLC codec libraries as high-risk components in their environments given their ubiquity and the media-parsing demands they handle; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Videolan over time
Signals from CVEs in this vendor scope (128 CVEs).
128 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-3275HIGH libdirectx_plugin.dll in VideoLAN VLC Media Player before 1.1.8 allows remote attackers to execute arbitrary code via a crafted width in an AMV file, related to a "dangling pointer | Mar 28, 2011 | 9.3 | 85 | NO | YES |
CVE-2008-4654HIGH Stack-based buffer overflow in the parse_master function in the Ty demux plugin (modules/demux/ty.c) in VLC Media Player 0.9.0 through 0.9.4 allows remote attackers to execute arbi | Oct 22, 2008 | 9.3 | 77 | NO | YES |
CVE-2012-1775HIGH Stack-based buffer overflow in VideoLAN VLC media player before 2.0.1 allows remote attackers to execute arbitrary code via a crafted MMS:// stream. | Mar 19, 2012 | 9.3 | 72 | NO | YES |
CVE-2011-0531HIGH demux/mkv/mkv.hpp in the MKV demuxer plugin in VideoLAN VLC media player 1.1.6.1 and earlier allows remote attackers to cause a denial of service (crash) and execute arbitrary comm | Feb 7, 2011 | 9.3 | 72 | NO | YES |
CVE-2008-5036HIGH Stack-based buffer overflow in VideoLAN VLC media player 0.9.x before 0.9.6 might allow user-assisted attackers to execute arbitrary code via an an invalid RealText (rt) subtitle f | Nov 10, 2008 | 9.3 | 72 | NO | YES |
CVE-2018-11529HIGH VideoLAN VLC media player 2.2.x is prone to a use after free vulnerability which an attacker can leverage to execute arbitrary code via crafted MKV files. Failed exploit attempts w | Jul 11, 2018 | 8.0 | 68 | NO | YES |
CVE-2011-0522MEDIUM The StripTags function in (1) the USF decoder (modules/codec/subtitles/subsdec.c) and (2) the Text decoder (modules/codec/subtitles/subsusf.c) in VideoLAN VLC Media Player 1.1 befo | Feb 7, 2011 | 6.8 | 62 | NO | YES |
CVE-2009-2484HIGH Stack-based buffer overflow in the Win32AddConnection function in modules/access/smb.c in VideoLAN VLC media player 0.9.9, when running on Microsoft Windows, allows remote attacker | Jul 16, 2009 | 9.3 | 61 | NO | YES |
CVE-2016-5108CRITICAL Buffer overflow in the DecodeAdpcmImaQT function in modules/codec/adpcm.c in VideoLAN VLC media player before 2.2.4 allows remote attackers to cause a denial of service (crash) or | Jun 8, 2016 | 9.8 | 56 | NO | YES |
CVE-2010-3124HIGH Untrusted search path vulnerability in bin/winvlc.c in VLC Media Player 1.1.3 and earlier allows local users, and possibly remote attackers, to execute arbitrary code and conduct D | Aug 26, 2010 | 9.3 | 44 | NO | YES |
Signals from CVEs in this vendor scope (128 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Videolan.
Media articles that mention a CVE ID that affects a product developed by Videolan — matched by CVE ID, not by vendor name.