CVE-2012-0023: Videolan Vlc Media Player

High severity, CVSS 9.3. EPSS: 4.9% chance of exploitation in the next 30 days.

Double free vulnerability in the get_chunk_header function in modules/demux/ty.c in VideoLAN VLC media player 0.9.0 through 1.1.12 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TiVo (TY) file.

Affected products

  • Videolan Vlc Media Player: version 0.9.0 only; version 0.9.1 only; version 0.9.2 only; version 0.9.3 only; version 0.9.4 only; version 0.9.5 only; …

Published 2012-10-30. Last modified 2026-06-16.