The picture_pool_Delete function in misc/picture_pool.c in VideoLAN VLC media player 2.1.5 allows remote attackers to execute arbitrary code or cause a denial of service (DEP violation and application crash) via a crafted FLV file.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.085
EPSS Ranking 92.0%