CVE-2021-25801

HIGH

Videolan Vlc Media Player - Out-of-Bounds Read

Title source: rule
STIX 2.1

Description

A buffer overflow vulnerability in the __Parse_indx component of VideoLAN VLC Media Player 3.0.11 allows attackers to cause an out-of-bounds read via a crafted .avi file.

Exploits (1)

nomisec WRITEUP
by DShankle · poc
https://github.com/DShankle/VLC_CVE-2021-25801_Analysis

References (1)

Core 1

Scores

CVSS v3 7.1
EPSS 0.0232
EPSS Percentile 84.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H

Details

CWE
CWE-125
Status published
Products (1)
videolan/vlc_media_player 3.0.11
Published Jul 26, 2021
Tracked Since Feb 18, 2026