CVE-2013-3564: Videolan Vlc Media Player
Medium severity, CVSS 5.3. EPSS: 1.1% chance of exploitation in the next 30 days.
The web interface in VideoLAN VLC media player before 2.0.7 has no access control which allows remote attackers to view directory listings via the 'dir' command or issue other commands without authenticating.
Affected products
- Videolan Vlc Media Player: before 2.0.7 (fixed in 2.0.7)
Published 2020-02-06. Last modified 2026-06-16.