CVE-2019-19721: Videolan Vlc Media Player

High severity, CVSS 7.8. EPSS: 2% chance of exploitation in the next 30 days.

An off-by-one error in the DecodeBlock function in codec/sdl_image.c in VideoLAN VLC media player before 3.0.9 allows remote attackers to cause a denial of service (memory corruption) via a crafted image file. NOTE: this may be related to the SDL_Image product.

Affected products

  • Videolan Vlc Media Player: before 3.0.9 (fixed in 3.0.9)

Published 2020-05-15. Last modified 2026-10-08.