Vulnerabilities
Vulnerable Software
Videolan:  >> Vlc  >> 0.8.6e  Security Vulnerabilities
Untrusted search path vulnerability in VideoLAN VLC before 0.9.0 allows local users to execute arbitrary code via a malicious library under the modules/ or plugins/ subdirectories of the current working directory.
CVSS Score
4.6
EPSS Score
0.003
Published
2008-05-12
Multiple integer overflows in VLC before 0.8.6f allow remote attackers to cause a denial of service (crash) via the (1) MP4 demuxer, (2) Real demuxer, and (3) Cinepak codec, which triggers a buffer overflow.
CVSS Score
6.8
EPSS Score
0.021
Published
2008-04-25
VLC before 0.8.6f allow remote attackers to cause a denial of service (crash) via a crafted Cinepak file that triggers an out-of-bounds array access and memory corruption.
CVSS Score
6.8
EPSS Score
0.141
Published
2008-04-25
Stack-based buffer overflow in the ParseSSA function (modules/demux/subtitle.c) in VLC 0.8.6e allows remote attackers to execute arbitrary code via a long subtitle in an SSA file. NOTE: this issue is due to an incomplete fix for CVE-2007-6681.
CVSS Score
6.8
EPSS Score
0.43
Published
2008-04-17
Integer overflow in the MP4_ReadBox_rdrf function in libmp4.c for VLC 0.8.6e allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted MP4 RDRF box that triggers a heap-based buffer overflow, a different vulnerability than CVE-2008-0984.
CVSS Score
6.8
EPSS Score
0.338
Published
2008-03-25


Contact Us

Shodan ® - All rights reserved