CVE-2017-10699: Videolan Vlc Media Player

Critical severity, CVSS 9.8. EPSS: 4.5% chance of exploitation in the next 30 days.

avcodec 2.2.x, as used in VideoLAN VLC media player 2.2.7-x before 2017-06-29, allows out-of-bounds heap memory write due to calling memcpy() with a wrong size, leading to a denial of service (application crash) or possibly code execution.

Affected products

  • Videolan Vlc Media Player: version 2.2.0 only; version 2.2.1 only; version 2.2.2 only; version 2.2.3 only; version 2.2.4 only; version 2.2.5 only; …

Published 2017-06-30. Last modified 2026-06-17.