← All CVEs

CVE-2007-3316

high · 9.3

Multiple format string vulnerabilities in plugins in VideoLAN VLC Media Player before 0.8.6c allow remote attackers to cause a denial of service (crash) or execute arbitrary code via format string specifiers in (1) an Ogg/Vorbis file, (2) an Ogg/Theora file, (3) a CDDB entry for a CD Digital Audio (CDDA) file, or (4) Service Announce Protocol (SAP) multicast packets.

9.3
CVSS
17.1%
EPSS (exploit prob.)
97th
EPSS percentile
2007-06-21
Published

AV:N/AC:M/Au:N/C:C/I:C/A:C

Affected products

VendorProductAffected versions
videolanvlc_media_player0.8.6a
videolanvlc_media_player0.8.6b

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2007-3316