CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

videolan

vlc_media_player

40 known vulnerabilities · sorted by CVSS score

CVE-2019-13962
CRITICAL9.8

lavc_CopyPicture in modules/codec/avcodec/video.c in VideoLAN VLC media player through 3.0.7 has a heap-based buffer over-read because it does not properly validate the width and height.

videolan / vlc_media_player+8
Network
Published Jul 18, 2019
Page 1 of 2
CVE-2023-47359
CRITICAL9.8

Videolan VLC prior to version 3.0.20 contains an incorrect offset read that leads to a Heap-Based Buffer Overflow in function GetPacket() and results in a memory corruption.

videolan / vlc_media_player
Network
Published Nov 7, 2023
CVE-2019-12874
CRITICAL9.8

An issue was discovered in zlib_decompress_extra in modules/demux/mkv/util.cpp in VideoLAN VLC media player 3.x through 3.0.7. The Matroska demuxer, while parsing a malformed MKV file type, has a double free.

videolan / vlc_media_player
Network
Published Jun 18, 2019
CVE-2018-19857
CRITICAL9.1

The CAF demuxer in modules/demux/caf.c in VideoLAN VLC media player 3.0.4 may read memory from an uninitialized pointer when processing magic cookies in CAF files, because a ReadKukiChunk() cast converts a return value to an unsigned int even if that value is negative. This could result in a denial of service and/or a potential infoleak.

videolan / vlc_media_player+1
Network
Published Dec 5, 2018
CVE-2018-11516
HIGH8.8

The vlc_demux_chained_Delete function in input/demux_chained.c in VideoLAN VLC media player 3.0.1 allows remote attackers to cause a denial of service (heap corruption and application crash) or possibly have unspecified other impact via a crafted .swf file.

videolan / vlc_media_player+1
Network
Published May 28, 2018
CVE-2018-11529
HIGH8.0

VideoLAN VLC media player 2.2.x is prone to a use after free vulnerability which an attacker can leverage to execute arbitrary code via crafted MKV files. Failed exploit attempts will likely result in denial of service conditions.

debian / debian_linux+1
Adjacent
Published Jul 11, 2018
CVE-2014-9626
HIGH7.8

Integer underflow in the MP4_ReadBox_String function in modules/demux/mp4/libmp4.c in VideoLAN VLC media player before 2.1.6 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a box size less than 7.

videolan / vlc_media_player
Local
Published Jan 24, 2020
CVE-2019-14778
HIGH7.8

The mkv::virtual_segment_c::seek method of demux/mkv/virtual_segment.cpp in VideoLAN VLC media player 3.0.7.1 has a use-after-free.

videolan / vlc_media_player+2
Local
Published Aug 29, 2019
CVE-2014-9628
HIGH7.8

The MP4_ReadBox_String function in modules/demux/mp4/libmp4.c in VideoLAN VLC media player before 2.1.6 allows remote attackers to trigger an unintended zero-size malloc and conduct buffer overflow attacks, and consequently execute arbitrary code, via a box size of 7.

videolan / vlc_media_player
Local
Published Jan 24, 2020
CVE-2019-14533
HIGH7.8

The Control function of demux/asf/asf.c in VideoLAN VLC media player 3.0.7.1 has a use-after-free.

videolan / vlc_media_player+2
Local
Published Aug 29, 2019
CVE-2019-14535
HIGH7.8

A divide-by-zero error exists in the SeekIndex function of demux/asf/asf.c in VideoLAN VLC media player 3.0.7.1. As a result, an FPE can be triggered via a crafted WMV file.

videolan / vlc_media_player+2
Local
Published Aug 29, 2019
CVE-2019-13602
HIGH7.8

An Integer Underflow in MP4_EIA608_Convert() in modules/demux/mp4/mp4.c in VideoLAN VLC media player through 3.0.7.1 allows remote attackers to cause a denial of service (heap-based buffer overflow and crash) or possibly have unspecified other impact via a crafted .mp4 file.

videolan / vlc_media_player+8
Local
Published Jul 14, 2019
CVE-2020-26664
HIGH7.8

A vulnerability in EbmlTypeDispatcher::send in VideoLAN VLC media player 3.0.11 allows attackers to trigger a heap-based buffer overflow via a crafted .mkv file.

videolan / vlc_media_player+2
Local
Published Jan 8, 2021
CVE-2019-14498
HIGH7.8

A divide-by-zero error exists in the Control function of demux/caf.c in VideoLAN VLC media player 3.0.7.1. As a result, an FPE can be triggered via a crafted CAF file.

videolan / vlc_media_player+2
Local
Published Aug 29, 2019
CVE-2019-14970
HIGH7.8

A vulnerability in mkv::event_thread_t in VideoLAN VLC media player 3.0.7.1 allows remote attackers to trigger a heap-based buffer overflow via a crafted .mkv file.

videolan / vlc_media_player+2
Local
Published Aug 29, 2019
CVE-2019-19721
HIGH7.8

An off-by-one error in the DecodeBlock function in codec/sdl_image.c in VideoLAN VLC media player before 3.0.9 allows remote attackers to cause a denial of service (memory corruption) via a crafted image file. NOTE: this may be related to the SDL_Image product.

videolan / vlc_media_player
Local
Published May 15, 2020
CVE-2022-41325
HIGH7.8

An integer overflow in the VNC module in VideoLAN VLC Media Player through 3.0.17.4 allows attackers, by tricking a user into opening a crafted playlist or connecting to a rogue VNC server, to crash VLC or execute code under some conditions.

videolan / vlc_media_player+1
Local
Published Dec 6, 2022
CVE-2019-18278
HIGH7.8

When executing VideoLAN VLC media player 3.0.8 with libqt on Windows, Data from a Faulting Address controls Code Flow starting at libqt_plugin!vlc_entry_license__3_0_0f+0x00000000003b9aba. NOTE: the VideoLAN security team indicates that they have not been contacted, and have no way of reproducing this issue.

videolan / vlc_media_player
Local
Published Oct 23, 2019
CVE-2019-14438
HIGH7.8

A heap-based buffer over-read in xiph_PackHeaders() in modules/demux/xiph.h in VideoLAN VLC media player 3.0.7.1 allows remote attackers to trigger a heap-based buffer over-read via a crafted .ogg file.

videolan / vlc_media_player+2
Local
Published Aug 29, 2019
CVE-2014-9627
HIGH7.8

The MP4_ReadBox_String function in modules/demux/mp4/libmp4.c in VideoLAN VLC media player before 2.1.6 performs an incorrect cast operation from a 64-bit integer to a 32-bit integer, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a large box size.

videolan / vlc_media_player
Local
Published Jan 24, 2020