CVE-2017-9300: Videolan Vlc Media Player

High severity, CVSS 7.8. EPSS: 3.4% chance of exploitation in the next 30 days.

plugins\codec\libflac_plugin.dll in VideoLAN VLC media player 2.2.4 allows remote attackers to cause a denial of service (heap corruption and application crash) or possibly have unspecified other impact via a crafted FLAC file.

Affected products

  • Videolan Vlc Media Player: up to and including 2.2.4

Published 2017-05-29. Last modified 2026-06-17.