CVE-2019-19721: Videolan Vlc Media Player
High severity, CVSS 7.8. EPSS: 2% chance of exploitation in the next 30 days.
An off-by-one error in the DecodeBlock function in codec/sdl_image.c in VideoLAN VLC media player before 3.0.9 allows remote attackers to cause a denial of service (memory corruption) via a crafted image file. NOTE: this may be related to the SDL_Image product.
Affected products
- Videolan Vlc Media Player: before 3.0.9 (fixed in 3.0.9)
Published 2020-05-15. Last modified 2026-10-08.