VendorsVideoLANvlc_media_player3.0.4
Vulnerabilities

VideoLAN VLC Media Player 3.0.4

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1CVEs
CVE-2018-19857
The CAF demuxer in modules/demux/caf.c in VideoLAN VLC media player 3.0.4 may read memory from an uninitialized pointer when processing magic cookies in CAF files, because a ReadKukiChunk() cast converts a return value to an unsigned int even if that value is negative. This could result in a denial of service and/or a potential infoleak.
Published 2018-12-05 · Modified
9.1EPSS 0.039