CVE-2019-19721High· 7.8▾ TwilightAn off-by-one error in the DecodeBlock function in codec/sdl_image.c in VideoLAN VLC media player before 3.0.9 allows remote attackers to cause a denial of service (memory corruption) via a crafted image file. NOTE: this may be related t…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 42.9 · likelihood 0.4 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
2.0%
An off-by-one error in the DecodeBlock function in codec/sdl_image.c in VideoLAN VLC media player before 3.0.9 allows remote attackers to cause a denial of service (memory corruption) via a crafted image file. NOTE: this may be related to the SDL_Image product.
vlc_media_player < 3.0.9Upgrade past the affected range:
vlc_media_player 3.0.9Connected by shared product, vendor, weakness, or advisory.
CVE-2019-13602High· 7.8An Integer Underflow in MP4_EIA608_Convert() in modules/demux/mp4/mp4.c in VideoLAN VLC media player through 3.0.7.1 allows remote attackers to cause a denial of service (heap-based buffer overflow and crash) or possibly have unspecified…
CVE-2020-26664High· 7.8A vulnerability in EbmlTypeDispatcher::send in VideoLAN VLC media player 3.0.11 allows attackers to trigger a heap-based buffer overflow via a crafted .mkv file.
CVE-2019-5460Medium· 5.5Double Free in VLC versions <= 3.0.6 leads to a crash.
CVE-2019-13962Critical· 9.8lavc_CopyPicture in modules/codec/avcodec/video.c in VideoLAN VLC media player through 3.0.7 has a heap-based buffer over-read because it does not properly validate the width and height.
CVE-2019-5459High· 7.1An Integer underflow in VLC Media Player versions < 3.0.7 leads to an out-of-band read.
CVE-2026-56711High· 7.0VLC media player versions 3.0.0 through 3.0.23 contain a memory-safety vulnerability reachable when processing crafted media