CVE-2021-25803

HIGH

VLC Media Player 3.0.11 - Buffer Overflow via Crafted .avi File

Title source: llm
STIX 2.1

Description

A buffer overflow vulnerability in the vlc_input_attachment_New component of VideoLAN VLC Media Player 3.0.11 allows attackers to cause an out-of-bounds read via a crafted .avi file.

References (1)

Core 1

Scores

CVSS v3 7.1
EPSS 0.0077
EPSS Percentile 50.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H

Details

CWE
CWE-190
Status published
Products (1)
videolan/vlc_media_player 3.0.11
Published Jul 26, 2021
Tracked Since Feb 18, 2026