CVE-2024-46461
EUVD-2024-4184425.09.2024, 15:15
VLC media player 3.0.20 and earlier is vulnerable to denial of service through an integer overflow which could be triggered with a maliciously crafted mms stream (heap based overflow). If successful, a malicious third party could trigger either a crash of VLC or an arbitrary code execution with the target user's privileges.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| videolan | vlc_media_player | 𝑥 ≤ 3.0.20 | ADP |
Debian Releases
Ubuntu Releases