Vlc

Vendor:

First CVE: Jan 17, 2008 · Active for 18 years

10
Total CVEs
More Total CVEs than 88% of tracked products
5.0
Avg CVEs / Year
Higher CVE frequency than 87% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 34% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Vlc over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 17, 2008
18 years ago
Most Recent CVE
Mar 28, 2017
3,405 days ago

CVE Severity & Scoring

Vlc10 CVEs
All CVEs352,294 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network1 (10.0%)
Unknown9 (90.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (10.0%)
High0 (0.0%)
Unknown9 (90.0%)
User Interaction
None1 (10.0%)
Unknown9 (90.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None1 (10.0%)
Unknown9 (90.0%)

Top CVEs

Signals from CVEs in this product scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Stack-based buffer overflow in modules/demux/subtitle.c in VideoLAN VLC 0.8.6d allows remote attackers to execute arbitrary code via a long subtitle in a (1) MicroDvd, (2) SSA, and
Jan 17, 20087.538NOYES
Format string vulnerability in the httpd_FileCallBack function (network/httpd.c) in VideoLAN VLC 0.8.6d allows remote attackers to execute arbitrary code via format string specifie
Jan 17, 20087.535NOYES
Integer overflow in the MP4_ReadBox_rdrf function in libmp4.c for VLC 0.8.6e allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a
Mar 25, 20086.834NOYES
Stack-based buffer overflow in the ParseSSA function (modules/demux/subtitle.c) in VLC 0.8.6e allows remote attackers to execute arbitrary code via a long subtitle in an SSA file.
Apr 17, 20086.833NOYES
VideoLAN VLC media player before 2.1.5 allows remote attackers to execute arbitrary code or cause a denial of service.
Mar 28, 20179.832NONO
VLC before 0.8.6f allow remote attackers to cause a denial of service (crash) via a crafted Cinepak file that triggers an out-of-bounds array access and memory corruption.
Apr 25, 20086.832NOYES
Multiple integer overflows in VLC before 0.8.6f allow remote attackers to cause a denial of service (crash) via the (1) MP4 demuxer, (2) Real demuxer, and (3) Cinepak codec, which
Apr 25, 20086.819NONO
The browser plugin in VideoLAN VLC 0.8.6d allows remote attackers to overwrite arbitrary files via (1) the :demuxdump-file option in a filename in a playlist, or (2) a EXTVLCOPT st
Jan 17, 20085.016NONO
The RTSP module in VideoLAN VLC 0.8.6d allows remote attackers to cause a denial of service (crash) via a request without a Transport parameter, which triggers a NULL pointer deref
Jan 17, 20085.015NONO
Untrusted search path vulnerability in VideoLAN VLC before 0.9.0 allows local users to execute arbitrary code via a malicious library under the modules/ or plugins/ subdirectories
May 12, 20084.614NONO

Exploit Exposure

Signals from CVEs in this product scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
5 CVEs
50.0% of CVEs· 91st percentile

Social Chatter

Signals from CVEs in this product scope (10 CVEs).

Media Mentions

Signals from CVEs in this product scope (10 CVEs).

Top CNAs Publishing CVEs For Vlc

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
0.8.6e56.46.8%03
0.8.6d55.63.1%01
0.8.6c36.13.4%01
0.8.6b36.13.4%01
0.8.6a36.13.4%01
0.8.626.84.9%01
0.8.536.13.4%01
0.8.4a36.13.4%01
0.8.436.13.4%01
0.8.236.13.4%01
0.8.133726.84.9%01
0.8.136.13.4%01
0.8.036.13.4%01
0.7.236.13.4%01
0.7.136.13.4%01
0.7.036.13.4%01
0.6.236.13.4%01
0.6.136.13.4%01
0.6.036.13.4%01
0.5.336.13.4%01