Vlc
Vendor:
First CVE: Jan 17, 2008 · Active for 18 years
10
Total CVEs
More Total CVEs than 88% of tracked products
5.0
Avg CVEs / Year
Higher CVE frequency than 87% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 34% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Vlc over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 17, 2008
18 years ago
Most Recent CVE
Mar 28, 2017
3,405 days ago
CVE Severity & Scoring
Vlc10 CVEs
70%
20%
10%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network1 (10.0%)
Unknown9 (90.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (10.0%)
High0 (0.0%)
Unknown9 (90.0%)
User Interaction
None1 (10.0%)
Unknown9 (90.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None1 (10.0%)
Unknown9 (90.0%)
Top CVEs
Signals from CVEs in this product scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-6681HIGH Stack-based buffer overflow in modules/demux/subtitle.c in VideoLAN VLC 0.8.6d allows remote attackers to execute arbitrary code via a long subtitle in a (1) MicroDvd, (2) SSA, and | Jan 17, 2008 | 7.5 | 38 | NO | YES |
CVE-2007-6682HIGH Format string vulnerability in the httpd_FileCallBack function (network/httpd.c) in VideoLAN VLC 0.8.6d allows remote attackers to execute arbitrary code via format string specifie | Jan 17, 2008 | 7.5 | 35 | NO | YES |
CVE-2008-1489MEDIUM Integer overflow in the MP4_ReadBox_rdrf function in libmp4.c for VLC 0.8.6e allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a | Mar 25, 2008 | 6.8 | 34 | NO | YES |
CVE-2008-1881MEDIUM Stack-based buffer overflow in the ParseSSA function (modules/demux/subtitle.c) in VLC 0.8.6e allows remote attackers to execute arbitrary code via a long subtitle in an SSA file. | Apr 17, 2008 | 6.8 | 33 | NO | YES |
CVE-2014-6440CRITICAL VideoLAN VLC media player before 2.1.5 allows remote attackers to execute arbitrary code or cause a denial of service. | Mar 28, 2017 | 9.8 | 32 | NO | NO |
CVE-2008-1769MEDIUM VLC before 0.8.6f allow remote attackers to cause a denial of service (crash) via a crafted Cinepak file that triggers an out-of-bounds array access and memory corruption. | Apr 25, 2008 | 6.8 | 32 | NO | YES |
CVE-2008-1768MEDIUM Multiple integer overflows in VLC before 0.8.6f allow remote attackers to cause a denial of service (crash) via the (1) MP4 demuxer, (2) Real demuxer, and (3) Cinepak codec, which | Apr 25, 2008 | 6.8 | 19 | NO | NO |
CVE-2007-6683MEDIUM The browser plugin in VideoLAN VLC 0.8.6d allows remote attackers to overwrite arbitrary files via (1) the :demuxdump-file option in a filename in a playlist, or (2) a EXTVLCOPT st | Jan 17, 2008 | 5.0 | 16 | NO | NO |
CVE-2007-6684MEDIUM The RTSP module in VideoLAN VLC 0.8.6d allows remote attackers to cause a denial of service (crash) via a request without a Transport parameter, which triggers a NULL pointer deref | Jan 17, 2008 | 5.0 | 15 | NO | NO |
CVE-2008-2147MEDIUM Untrusted search path vulnerability in VideoLAN VLC before 0.9.0 allows local users to execute arbitrary code via a malicious library under the modules/ or plugins/ subdirectories | May 12, 2008 | 4.6 | 14 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (10 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
5 CVEs
50.0% of CVEs· 91st percentile
Social Chatter
Signals from CVEs in this product scope (10 CVEs).
Media Mentions
Signals from CVEs in this product scope (10 CVEs).
Top CNAs Publishing CVEs For Vlc
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 0.8.6e | 5 | 6.4 | 6.8% | 0 | 3 |
| 0.8.6d | 5 | 5.6 | 3.1% | 0 | 1 |
| 0.8.6c | 3 | 6.1 | 3.4% | 0 | 1 |
| 0.8.6b | 3 | 6.1 | 3.4% | 0 | 1 |
| 0.8.6a | 3 | 6.1 | 3.4% | 0 | 1 |
| 0.8.6 | 2 | 6.8 | 4.9% | 0 | 1 |
| 0.8.5 | 3 | 6.1 | 3.4% | 0 | 1 |
| 0.8.4a | 3 | 6.1 | 3.4% | 0 | 1 |
| 0.8.4 | 3 | 6.1 | 3.4% | 0 | 1 |
| 0.8.2 | 3 | 6.1 | 3.4% | 0 | 1 |
| 0.8.1337 | 2 | 6.8 | 4.9% | 0 | 1 |
| 0.8.1 | 3 | 6.1 | 3.4% | 0 | 1 |
| 0.8.0 | 3 | 6.1 | 3.4% | 0 | 1 |
| 0.7.2 | 3 | 6.1 | 3.4% | 0 | 1 |
| 0.7.1 | 3 | 6.1 | 3.4% | 0 | 1 |
| 0.7.0 | 3 | 6.1 | 3.4% | 0 | 1 |
| 0.6.2 | 3 | 6.1 | 3.4% | 0 | 1 |
| 0.6.1 | 3 | 6.1 | 3.4% | 0 | 1 |
| 0.6.0 | 3 | 6.1 | 3.4% | 0 | 1 |
| 0.5.3 | 3 | 6.1 | 3.4% | 0 | 1 |