{"id":"CVE-2020-26664","title":"A vulnerability in EbmlTypeDispatcher::send in VideoLAN VLC media player 3.0.11 allows attackers to trigger a heap-based buffer overflow via a crafted .mkv file.","summary":"A vulnerability in EbmlTypeDispatcher::send in VideoLAN VLC media player 3.0.11 allows attackers to trigger a heap-based buffer overflow via a crafted .mkv file.","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","cwe":["CWE-787"],"vendor":"videolan","product":"vlc_media_player","affected":["vlc_media_player < 3.0.12","debian_linux = 9.0","debian_linux = 10.0"],"patched":["vlc_media_player 3.0.12"],"published":"2021-01-08","updated":"2026-07-05","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2020-26664","references":[{"url":"http://videolan.com","label":"cve@mitre.org"},{"url":"https://gist.githubusercontent.com/henices/db11664dd45b9f322f8514d182aef5ea/raw/d56940c8bf211992bf4f3309a85bb2b69383e511/CVE-2020-26664.txt","label":"cve@mitre.org"},{"url":"https://lists.debian.org/debian-lts-announce/2022/06/msg00012.html","label":"cve@mitre.org"},{"url":"https://security.gentoo.org/glsa/202101-37","label":"cve@mitre.org"},{"url":"https://www.debian.org/security/2021/dsa-4834","label":"cve@mitre.org"},{"url":"http://videolan.com","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://vlc.com","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://gist.githubusercontent.com/henices/db11664dd45b9f322f8514d182aef5ea/raw/d56940c8bf211992bf4f3309a85bb2b69383e511/CVE-2020-26664.txt","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2022/06/msg00012.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.gentoo.org/glsa/202101-37","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.debian.org/security/2021/dsa-4834","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.01473,"epssPercentile":0.72657,"ingestedAt":"2026-07-05T00:59:25.770Z","slug":"CVE-2020-26664","body":"## Overview\n\nA vulnerability in EbmlTypeDispatcher::send in VideoLAN VLC media player 3.0.11 allows attackers to trigger a heap-based buffer overflow via a crafted .mkv file.\n\n## Affected\n\n- `vlc_media_player < 3.0.12`\n- `debian_linux = 9.0`\n- `debian_linux = 10.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `vlc_media_player 3.0.12`","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":42.9,"likelihood":0.3,"exploitation":0,"ransomware":0},"changes":[]}