Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:26071
HistoryAug 06, 2020 - 9:28 p.m.

Arbtirary Code Execution

2020-08-0621:28:39
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9

0.006 Low

EPSS

Percentile

78.6%

vlc is vulnerable to arbitrary code execution. A heap-based buffer overflow in the hxxx_AnnexB_to_xVC function in modules/packetizer/hxxx_nal.c allows a remote attacker to cause a denial of service (application crash) or execute arbitrary code via a malicious H.264 Annex-B video (.avi for example) file.