CVE-2025-51602: Videolan Vlc Media Player

Medium severity, CVSS 4.8. EPSS: 0.4% chance of exploitation in the next 30 days.

mmstu.c in VideoLAN VLC media player before 3.0.22 allows an out-of-bounds read and denial of service via a crafted 0x01 response from an MMS server.

Affected products

  • Videolan Vlc Media Player: before 3.0.22 (fixed in 3.0.22)

Published 2026-01-16. Last modified 2026-06-17.