CVE-2007-6262

VideoLAN VLC <0.8.6d - RCE

Title source: llm

Description

A certain ActiveX control in axvlc.dll in VideoLAN VLC 0.8.6 before 0.8.6d allows remote attackers to execute arbitrary code via crafted arguments to the (1) addTarget, (2) getVariable, or (3) setVariable function, resulting from a "bad initialized pointer," aka a "recursive plugin release vulnerability."

Exploits (1)

exploitdb WORKING POC VERIFIED
by Ricardo Narvaja · htmldoswindows
https://www.exploit-db.com/exploits/4688

Scores

EPSS 0.2280
EPSS Percentile 95.9%

Details

CWE
CWE-119
Status published
Products (3)
videolan/vlc_media_player 0.8.6
videolan/vlc_media_player 0.8.6a
videolan/vlc_media_player 0.8.6b
Published Dec 06, 2007
Tracked Since Feb 18, 2026