CVE-2016-5108
CRITICALDebian Linux < 2.2.3 - Memory Corruption
Title source: ruleDescription
Buffer overflow in the DecodeAdpcmImaQT function in modules/codec/adpcm.c in VideoLAN VLC media player before 2.2.4 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted QuickTime IMA file.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Patrick Coleman · textdoswindows
https://www.exploit-db.com/exploits/41025
References (6)
Scores
CVSS v3
9.8
EPSS
0.2082
EPSS Percentile
95.6%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-119
Status
published
Products (2)
debian/debian_linux
8.0
videolan/vlc_media_player
< 2.2.3
Published
Jun 08, 2016
Tracked Since
Feb 18, 2026