Search CVE reports


Toggle filters

31 – 40 of 153 results


CVE-2019-14533

Medium priority

Some fixes available 2 of 3

The Control function of demux/asf/asf.c in VideoLAN VLC media player 3.0.7.1 has a use-after-free.

1 affected package

vlc

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
vlc Not affected Not affected Not affected Fixed
Show less packages

CVE-2019-14498

Medium priority

Some fixes available 2 of 3

A divide-by-zero error exists in the Control function of demux/caf.c in VideoLAN VLC media player 3.0.7.1. As a result, an FPE can be triggered via a crafted CAF file.

1 affected package

vlc

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
vlc Not affected Not affected Not affected Fixed
Show less packages

CVE-2019-14438

Medium priority

Some fixes available 2 of 3

A heap-based buffer over-read in xiph_PackHeaders() in modules/demux/xiph.h in VideoLAN VLC media player 3.0.7.1 allows remote attackers to trigger a heap-based buffer over-read via a crafted .ogg file.

1 affected package

vlc

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
vlc Not affected Not affected Not affected Fixed
Show less packages

CVE-2019-14437

Medium priority

Some fixes available 2 of 3

The xiph_SplitHeaders function in modules/demux/xiph.h in VideoLAN VLC media player 3.0.7.1 does not check array bounds properly. As a result, a heap-based buffer over-read can be triggered via a crafted .ogg file.

1 affected package

vlc

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
vlc Not affected Not affected Not affected Fixed
Show less packages

CVE-2019-13962

Low priority

Some fixes available 2 of 3

lavc_CopyPicture in modules/codec/avcodec/video.c in VideoLAN VLC media player through 3.0.7 has a heap-based buffer over-read because it does not properly validate the width and height.

1 affected package

vlc

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
vlc Not affected Not affected Not affected Fixed
Show less packages

CVE-2019-13615

Low priority

Some fixes available 2 of 3

libebml before 1.3.6, as used in the MKV module in VideoLAN VLC Media Player binaries before 3.0.3, has a heap-based buffer over-read in EbmlElement::FindNextElement.

2 affected packages

libebml, vlc

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libebml Fixed
vlc Not affected
Show less packages

CVE-2019-13602

Medium priority

Some fixes available 2 of 4

An Integer Underflow in MP4_EIA608_Convert() in modules/demux/mp4/mp4.c in VideoLAN VLC media player through 3.0.7.1 allows remote attackers to cause a denial of service (heap-based buffer overflow and crash) or possibly...

1 affected package

vlc

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
vlc Not affected Not affected Not affected Fixed
Show less packages

CVE-2019-12874

Medium priority

Some fixes available 2 of 4

An issue was discovered in zlib_decompress_extra in modules/demux/mkv/util.cpp in VideoLAN VLC media player 3.x through 3.0.7. The Matroska demuxer, while parsing a malformed MKV file type, has a double free.

1 affected package

vlc

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
vlc Not affected Not affected Not affected Fixed
Show less packages

CVE-2018-7751

Medium priority

Some fixes available 1 of 40

The svg_probe function in libavformat/img2dec.c in FFmpeg through 3.4.2 allows remote attackers to cause a denial of service (Infinite Loop) via a crafted XML file.

7 affected packages

gst-libav1.0, mythtv, ffmpeg, libav, mplayer...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gst-libav1.0 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
mythtv Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ffmpeg Not affected Not affected Not affected Fixed
libav Not in release Not in release Not in release Not in release
mplayer Not affected Not affected Not affected Not affected
oxide-qt Not in release Not in release Not in release Not in release
vlc Not affected Not affected Not affected Not affected
Show all 7 packages Show less packages

CVE-2018-1999014

Medium priority
Needs evaluation

FFmpeg before commit bab0716c7f4793ec42e05a5aa7e80d82a0dd4e75 contains an out of array access vulnerability in MXF format demuxer that can result in DoS. This attack appear to be exploitable via specially crafted MXF file which...

7 affected packages

ffmpeg, qtwebengine-opensource-src, gst-libav1.0, kino, vlc...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ffmpeg Not affected Not affected Not affected Not affected
qtwebengine-opensource-src Needs evaluation Needs evaluation Needs evaluation Needs evaluation
gst-libav1.0 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
kino Not in release Needs evaluation Needs evaluation Needs evaluation
vlc Not affected Not affected Not affected Not affected
chromium-browser Ignored Ignored Not in release Ignored
oxide-qt Not in release Not in release Not in release Not in release
Show all 7 packages Show less packages