CVE-2015-5949: Videolan Vlc Media Player

Medium severity, CVSS 6.8. EPSS: 13.3% chance of exploitation in the next 30 days.

VideoLAN VLC media player 2.2.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted 3GP file, which triggers the freeing of arbitrary pointers.

Affected products

  • Videolan Vlc Media Player: up to and including 2.2.1

Published 2015-08-25. Last modified 2026-06-17.