CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

Search Vulnerabilities

 Software

Searching vulnerabilities affecting “videolan”

44 vulnerabilities found for “videolan”

Page 1 of 3

CVE-2023-46814
HIGH7.8

A binary hijacking vulnerability exists within the VideoLAN VLC media player before 3.0.19 on Windows. The uninstaller attempts to execute code with elevated privileges out of a standard user writable location. Standard users may use this to gain arbitrary code execution as SYSTEM.

videolan / vlc_media_player
Local
Published Nov 22, 2023
Page 1 of 3
CVE-2023-47359
CRITICAL9.8

Videolan VLC prior to version 3.0.20 contains an incorrect offset read that leads to a Heap-Based Buffer Overflow in function GetPacket() and results in a memory corruption.

videolan / vlc_media_player
Network
Published Nov 7, 2023
CVE-2023-47360
HIGH7.5

Videolan VLC prior to version 3.0.20 contains an Integer underflow that leads to an incorrect packet length.

videolan / vlc_media_player
Network
Published Nov 7, 2023
CVE-2022-41325
HIGH7.8

An integer overflow in the VNC module in VideoLAN VLC Media Player through 3.0.17.4 allows attackers, by tricking a user into opening a crafted playlist or connecting to a rogue VNC server, to crash VLC or execute code under some conditions.

videolan / vlc_media_player+1
Local
Published Dec 6, 2022
CVE-2021-25804
HIGH7.5

A NULL-pointer dereference in "Open" in avi.c of VideoLAN VLC Media Player 3.0.11 can a denial of service (DOS) in the application.

videolan / vlc_media_player
Network
Published Jul 26, 2021
CVE-2021-25802
HIGH7.1

A buffer overflow vulnerability in the AVI_ExtractSubtitle component of VideoLAN VLC Media Player 3.0.11 allows attackers to cause an out-of-bounds read via a crafted .avi file.

videolan / vlc_media_player
Local
Published Jul 26, 2021
CVE-2021-25803
HIGH7.1

A buffer overflow vulnerability in the vlc_input_attachment_New component of VideoLAN VLC Media Player 3.0.11 allows attackers to cause an out-of-bounds read via a crafted .avi file.

videolan / vlc_media_player
Local
Published Jul 26, 2021
CVE-2021-25801
HIGH7.1

A buffer overflow vulnerability in the __Parse_indx component of VideoLAN VLC Media Player 3.0.11 allows attackers to cause an out-of-bounds read via a crafted .avi file.

videolan / vlc_media_player
Local
Published Jul 26, 2021
CVE-2020-26664
HIGH7.8

A vulnerability in EbmlTypeDispatcher::send in VideoLAN VLC media player 3.0.11 allows attackers to trigger a heap-based buffer overflow via a crafted .mkv file.

videolan / vlc_media_player+2
Local
Published Jan 8, 2021
CVE-2020-13428
HIGH7.8

A heap-based buffer overflow in the hxxx_AnnexB_to_xVC function in modules/packetizer/hxxx_nal.c in VideoLAN VLC media player before 3.0.11 for macOS/iOS allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a crafted H.264 Annex-B video (.avi for example) file.

videolan / vlc_media_player+3
Local
Published Jun 8, 2020
CVE-2019-19721
HIGH7.8

An off-by-one error in the DecodeBlock function in codec/sdl_image.c in VideoLAN VLC media player before 3.0.9 allows remote attackers to cause a denial of service (memory corruption) via a crafted image file. NOTE: this may be related to the SDL_Image product.

videolan / vlc_media_player
Local
Published May 15, 2020
CVE-2015-7810
MEDIUM4.7

libbluray MountManager class has a time-of-check time-of-use (TOCTOU) race when expanding JAR files

videolan / libbluray+6
Local
Published Nov 22, 2019
CVE-2019-13962
CRITICAL9.8

lavc_CopyPicture in modules/codec/avcodec/video.c in VideoLAN VLC media player through 3.0.7 has a heap-based buffer over-read because it does not properly validate the width and height.

videolan / vlc_media_player+8
Network
Published Jul 18, 2019
CVE-2019-13615
MEDIUM5.5

libebml before 1.3.6, as used in the MKV module in VideoLAN VLC Media Player binaries before 3.0.3, has a heap-based buffer over-read in EbmlElement::FindNextElement.

videolan / vlc_media_player
Local
Published Jul 16, 2019
CVE-2019-13602
HIGH7.8

An Integer Underflow in MP4_EIA608_Convert() in modules/demux/mp4/mp4.c in VideoLAN VLC media player through 3.0.7.1 allows remote attackers to cause a denial of service (heap-based buffer overflow and crash) or possibly have unspecified other impact via a crafted .mp4 file.

videolan / vlc_media_player+8
Local
Published Jul 14, 2019
CVE-2019-12874
CRITICAL9.8

An issue was discovered in zlib_decompress_extra in modules/demux/mkv/util.cpp in VideoLAN VLC media player 3.x through 3.0.7. The Matroska demuxer, while parsing a malformed MKV file type, has a double free.

videolan / vlc_media_player
Network
Published Jun 18, 2019
CVE-2019-5439
MEDIUM6.5

A Buffer Overflow in VLC Media Player < 3.0.7 causes a crash which can possibly be further developed into a remote code execution exploit.

videolan / vlc_media_player
Network
Published Jun 13, 2019
CVE-2018-19857
CRITICAL9.1

The CAF demuxer in modules/demux/caf.c in VideoLAN VLC media player 3.0.4 may read memory from an uninitialized pointer when processing magic cookies in CAF files, because a ReadKukiChunk() cast converts a return value to an unsigned int even if that value is negative. This could result in a denial of service and/or a potential infoleak.

videolan / vlc_media_player+1
Network
Published Dec 5, 2018
CVE-2018-11529
HIGH8.0

VideoLAN VLC media player 2.2.x is prone to a use after free vulnerability which an attacker can leverage to execute arbitrary code via crafted MKV files. Failed exploit attempts will likely result in denial of service conditions.

debian / debian_linux+1
Adjacent
Published Jul 11, 2018
CVE-2018-11516
HIGH8.8

The vlc_demux_chained_Delete function in input/demux_chained.c in VideoLAN VLC media player 3.0.1 allows remote attackers to cause a denial of service (heap corruption and application crash) or possibly have unspecified other impact via a crafted .swf file.

videolan / vlc_media_player+1
Network
Published May 28, 2018