CVE-2024-46461: Videolan Vlc Media Player

High severity, CVSS 8.0. EPSS: 0.6% chance of exploitation in the next 30 days.

VLC media player 3.0.20 and earlier is vulnerable to denial of service through an integer overflow which could be triggered with a maliciously crafted mms stream (heap based overflow). If successful, a malicious third party could trigger either a crash of VLC or an arbitrary code execution with the target user's privileges.

Affected products

  • Videolan Vlc Media Player: up to and including 3.0.20

Published 2024-09-25. Last modified 2026-06-17.