CVE-2012-3377: Videolan Vlc Media Player

Medium severity, CVSS 6.8. EPSS: 3.8% chance of exploitation in the next 30 days.

Heap-based buffer overflow in the Ogg_DecodePacket function in the OGG demuxer (modules/demux/ogg.c) in VideoLAN VLC media player before 2.0.2 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted OGG file.

Affected products

  • Videolan Vlc Media Player: up to and including 2.0.1; version 0.1.99a only; version 0.1.99b only; version 0.1.99c only; version 0.1.99d only; version 0.1.99e only; …

Published 2012-07-12. Last modified 2026-06-16.