VLC media player 3.0.20 and earlier is vulnerable to denial of service through an integer overflow which could be triggered with a maliciously crafted mms stream (heap based overflow). If successful, a malicious third party could trigger either a crash of VLC or an arbitrary code execution with the target user's privileges.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.videolan.org/security/sb-vlc3021.html |
|
History
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 25 Sep 2024 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Videolan
Videolan vlc Media Player |
|
| Weaknesses | CWE-122 | |
| CPEs | cpe:2.3:a:videolan:vlc_media_player:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Videolan
Videolan vlc Media Player |
|
| Metrics |
cvssV3_1
|
Wed, 25 Sep 2024 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | VLC media player 3.0.20 and earlier is vulnerable to denial of service through an integer overflow which could be triggered with a maliciously crafted mms stream (heap based overflow). If successful, a malicious third party could trigger either a crash of VLC or an arbitrary code execution with the target user's privileges. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2024-09-25T00:00:00
Updated: 2024-09-25T15:39:36.371Z
Reserved: 2024-09-11T00:00:00
Link: CVE-2024-46461
Updated: 2024-09-25T15:39:31.700Z
Status : Awaiting Analysis
Published: 2024-09-25T15:15:14.567
Modified: 2024-09-26T13:32:02.803
Link: CVE-2024-46461
No data.
ReportizFlow