CVE-2019-5460Medium· 5.5▾ SunlitDouble Free in VLC versions <= 3.0.6 leads to a crash.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 30.3 · likelihood 0.5 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
2.5%
Double Free in VLC versions <= 3.0.6 leads to a crash.
vlc_media_player <= 3.0.6backports = sle-15leap = 15.0leap = 15.1Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2019-13962Critical· 9.8lavc_CopyPicture in modules/codec/avcodec/video.c in VideoLAN VLC media player through 3.0.7 has a heap-based buffer over-read because it does not properly validate the width and height.
CVE-2019-5459High· 7.1An Integer underflow in VLC Media Player versions < 3.0.7 leads to an out-of-band read.
CVE-2019-13602High· 7.8An Integer Underflow in MP4_EIA608_Convert() in modules/demux/mp4/mp4.c in VideoLAN VLC media player through 3.0.7.1 allows remote attackers to cause a denial of service (heap-based buffer overflow and crash) or possibly have unspecified…
CVE-2019-19721High· 7.8An off-by-one error in the DecodeBlock function in codec/sdl_image.c in VideoLAN VLC media player before 3.0.9 allows remote attackers to cause a denial of service (memory corruption) via a crafted image file
CVE-2020-26664High· 7.8A vulnerability in EbmlTypeDispatcher::send in VideoLAN VLC media player 3.0.11 allows attackers to trigger a heap-based buffer overflow via a crafted .mkv file.
CVE-2019-11049Medium· 6.5In PHP versions 7.3.x below 7.3.13 and 7.4.0 on Windows, when supplying custom headers to mail() function, due to mistake introduced in commit 78f4b4a2dcf92ddbccea1bb95f8390a18ac3342e, if the header is supplied in lowercase, this can res…