CVE-2013-1954: Videolan Vlc Media Player

Medium severity, CVSS 6.8. EPSS: 6.1% chance of exploitation in the next 30 days.

The ASF Demuxer (modules/demux/asf/asf.c) in VideoLAN VLC media player 2.0.5 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted ASF movie that triggers an out-of-bounds read.

Affected products

  • Videolan Vlc Media Player: up to and including 2.0.5; version 2.0.0 only; version 2.0.1 only; version 2.0.2 only; version 2.0.3 only; version 2.0.4 only

Published 2013-07-10. Last modified 2026-06-16.