Your submission was sent successfully! Close

Thank you for contacting us. A member of our team will be in touch shortly. Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

Search CVE reports


Toggle filters

31 – 40 of 150 results


CVE-2019-14778

Medium priority

Some fixes available 2 of 3

The mkv::virtual_segment_c::seek method of demux/mkv/virtual_segment.cpp in VideoLAN VLC media player 3.0.7.1 has a use-after-free.

1 affected packages

vlc

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
vlc Not affected Not affected Not affected Fixed Vulnerable
Show less packages

CVE-2019-14777

Medium priority

Some fixes available 2 of 3

The Control function of demux/mkv/mkv.cpp in VideoLAN VLC media player 3.0.7.1 has a use-after-free.

1 affected packages

vlc

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
vlc Not affected Not affected Not affected Fixed Vulnerable
Show less packages

CVE-2019-14776

Medium priority

Some fixes available 2 of 3

A heap-based buffer over-read exists in DemuxInit() in demux/asf/asf.c in VideoLAN VLC media player 3.0.7.1 via a crafted .mkv file.

1 affected packages

vlc

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
vlc Not affected Not affected Not affected Fixed Vulnerable
Show less packages

CVE-2019-14535

Medium priority

Some fixes available 2 of 3

A divide-by-zero error exists in the SeekIndex function of demux/asf/asf.c in VideoLAN VLC media player 3.0.7.1. As a result, an FPE can be triggered via a crafted WMV file.

1 affected packages

vlc

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
vlc Not affected Not affected Not affected Fixed Vulnerable
Show less packages

CVE-2019-14534

Medium priority

Some fixes available 2 of 3

In VideoLAN VLC media player 3.0.7.1, there is a NULL pointer dereference at the function SeekPercent of demux/asf/asf.c that will lead to a denial of service attack.

1 affected packages

vlc

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
vlc Not affected Not affected Not affected Fixed Vulnerable
Show less packages

CVE-2019-14533

Medium priority

Some fixes available 2 of 3

The Control function of demux/asf/asf.c in VideoLAN VLC media player 3.0.7.1 has a use-after-free.

1 affected packages

vlc

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
vlc Not affected Not affected Not affected Fixed Vulnerable
Show less packages

CVE-2019-14498

Medium priority

Some fixes available 2 of 3

A divide-by-zero error exists in the Control function of demux/caf.c in VideoLAN VLC media player 3.0.7.1. As a result, an FPE can be triggered via a crafted CAF file.

1 affected packages

vlc

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
vlc Not affected Not affected Not affected Fixed Vulnerable
Show less packages

CVE-2019-14438

Medium priority

Some fixes available 2 of 3

A heap-based buffer over-read in xiph_PackHeaders() in modules/demux/xiph.h in VideoLAN VLC media player 3.0.7.1 allows remote attackers to trigger a heap-based buffer over-read via a crafted .ogg file.

1 affected packages

vlc

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
vlc Not affected Not affected Not affected Fixed Vulnerable
Show less packages

CVE-2019-14437

Medium priority

Some fixes available 2 of 3

The xiph_SplitHeaders function in modules/demux/xiph.h in VideoLAN VLC media player 3.0.7.1 does not check array bounds properly. As a result, a heap-based buffer over-read can be triggered via a crafted .ogg file.

1 affected packages

vlc

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
vlc Not affected Not affected Not affected Fixed Vulnerable
Show less packages

CVE-2019-5460

Medium priority
Not affected

Double Free in VLC versions <= 3.0.6 leads to a crash.

1 affected packages

vlc

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
vlc Not affected Not affected
Show less packages