CVE-2013-1868: Videolan Vlc Media Player

High severity, CVSS 9.3. EPSS: 11% chance of exploitation in the next 30 days.

Multiple buffer overflows in VideoLAN VLC media player 2.0.4 and earlier allow remote attackers to cause a denial of service (crash) and execute arbitrary code via vectors related to the (1) freetype renderer and (2) HTML subtitle parser.

Affected products

  • Videolan Vlc Media Player: up to and including 2.0.4; version 2.0.0 only; version 2.0.1 only; version 2.0.2 only; version 2.0.3 only

Published 2013-07-10. Last modified 2026-06-16.