CVE-2009-2484
VLC media player <0.9.9 - Buffer Overflow
Title source: llmDescription
Stack-based buffer overflow in the Win32AddConnection function in modules/access/smb.c in VideoLAN VLC media player 0.9.9, when running on Microsoft Windows, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long smb URI in a playlist file.
Exploits (3)
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubylocalwindows_x86
https://www.exploit-db.com/exploits/16678
metasploit
WORKING POC
GREAT
by jduck · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/fileformat/vlc_smb_uri.rb
References (6)
Scores
EPSS
0.7123
EPSS Percentile
98.7%
Details
CWE
CWE-119
Status
published
Products (1)
videolan/vlc_media_player
0.9.9
Published
Jul 16, 2009
Tracked Since
Feb 18, 2026