
CVE-2010-3276 – Gentoo Linux Security Advisory 201411-01
https://notcve.org/view.php?id=CVE-2010-3276
28 Mar 2011 — libdirectx_plugin.dll in VideoLAN VLC Media Player before 1.1.8 allows remote attackers to execute arbitrary code via a crafted width in an NSV file. libdirectx_plugin.dll de VideoLAN VLC Media Player en versiones anteriores a v1.1.8 permite a atacantes remotos la ejecución de código arbitrario mediante la manipulación de la anchura en ficheros NSV Multiple vulnerabilities have been found in VLC, the worst of which could lead to user-assisted execution of arbitrary code. Versions less than 2.1.2 are affecte... • http://secunia.com/advisories/43826 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2011-0522 – VideoLAN VLC Media Player 1.1 - Subtitle 'StripTags()' Memory Corruption
https://notcve.org/view.php?id=CVE-2011-0522
07 Feb 2011 — The StripTags function in (1) the USF decoder (modules/codec/subtitles/subsdec.c) and (2) the Text decoder (modules/codec/subtitles/subsusf.c) in VideoLAN VLC Media Player 1.1 before 1.1.6-rc allows remote attackers to execute arbitrary code via a subtitle with an opening "<" without a closing ">" in an MKV file, which triggers heap memory corruption, as demonstrated using refined-australia-blu720p-sample.mkv. La función StripTags en (1) el decodificador USF (modules/codec/subtitles/subsdec.c) y (2) el deco... • https://www.exploit-db.com/exploits/16108 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2011-0531 – VideoLAN VLC Media Player 1.1.6 - 'MKV' Memory Corruption
https://notcve.org/view.php?id=CVE-2011-0531
07 Feb 2011 — demux/mkv/mkv.hpp in the MKV demuxer plugin in VideoLAN VLC media player 1.1.6.1 and earlier allows remote attackers to cause a denial of service (crash) and execute arbitrary commands via a crafted MKV (WebM or Matroska) file that triggers memory corruption, related to "class mismatching" and the MKV_IS_ID macro. demux/mkv/mkv.hpp en el plugin MKV demuxer en VideoLAN VLC Media Player v1.1.6.1 y anteriores permite a atacantes remotos causar una denegación de servicio (caída) y ejecutar comandos arbitrarios ... • https://www.exploit-db.com/exploits/16637 • CWE-20: Improper Input Validation •

CVE-2011-0021 – Gentoo Linux Security Advisory 201411-01
https://notcve.org/view.php?id=CVE-2011-0021
25 Jan 2011 — Multiple heap-based buffer overflows in cdg.c in the CDG decoder in VideoLAN VLC Media Player before 1.1.6 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted CDG video. Múltiples desbordamientos de búfer de la memoria dinámica en cdg.c del descodificador CDG para VideoLAN VLC Media Player anterior a v1.1.6 permite a atacantes remotos causar una denegación de servicio (caída de aplicación) o posiblemente ejecutar código de su elección a tr... • http://download.videolan.org/pub/videolan/vlc/1.1.6/vlc-1.1.6.tar.bz2 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2010-3907 – Gentoo Linux Security Advisory 201411-01
https://notcve.org/view.php?id=CVE-2010-3907
03 Jan 2011 — Multiple integer overflows in real.c in the Real demuxer plugin in VideoLAN VLC Media Player before 1.1.6 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a zero i_subpackets value in a Real Media file, leading to a heap-based buffer overflow. Múltiples desbordamientos de entero en real.c en el complemento Real demuxer en VideoLAN VLC Media Player anterior a v1.1.6 permite a atacantes remotos causar una denegación de servicio (caída de aplicación... • http://git.videolan.org/?p=vlc.git%3Ba=commit%3Bh=6568965770f906d34d4aef83237842a5376adb55 • CWE-189: Numeric Errors •