Code Flow Manipulation Vulnerability in VLC Media Player by VideoLAN
CVE-2019-18278
7.8HIGH
Summary
A vulnerability in VLC Media Player 3.0.8 allows for code flow manipulation due to a faulting address when executed with libqt on Windows. This flaw results in potential security risks, as maliciously crafted data may influence program behavior. The VideoLAN security team has noted that they have yet to receive reports or reproduction steps for this issue, highlighting the importance of user awareness and security practices.
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved