CVE-2019-18278: Videolan Vlc Media Player

High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.

When executing VideoLAN VLC media player 3.0.8 with libqt on Windows, Data from a Faulting Address controls Code Flow starting at libqt_plugin!vlc_entry_license__3_0_0f+0x00000000003b9aba. NOTE: the VideoLAN security team indicates that they have not been contacted, and have no way of reproducing this issue.

Affected products

  • Videolan Vlc Media Player: version 3.0.8 only

Published 2019-10-23. Last modified 2026-06-17.