Analysis and contextual insights are available on OpenCVE Cloud.
No solution or workaround provided in the CVE record.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-3150-1 | vlc security update |
EUVD |
EUVD-2014-9440 | The MP4_ReadBox_String function in modules/demux/mp4/libmp4.c in VideoLAN VLC media player before 2.1.6 allows remote attackers to trigger an unintended zero-size malloc and conduct buffer overflow attacks, and consequently execute arbitrary code, via a box size of 7. |
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T13:47:41.918Z
Reserved: 2015-01-20T00:00:00.000Z
Link: CVE-2014-9628
No data.
Status : Modified
Published: 2020-01-24T22:15:12.520
Modified: 2026-06-17T00:18:40.537
Link: CVE-2014-9628
No data.
OpenCVE Enrichment
No data.
-
CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Debian DSA
EUVD