peter bassill · operator
$ cve CVE-2007-6262 JSON

CVE-2007-6262 EXPLOIT

6.8
MEDIUM · CVSS 2.0 · EPSS 11.1% (pctl 96)

Patch early

A public exploit exists.

Description

A certain ActiveX control in axvlc.dll in VideoLAN VLC 0.8.6 before 0.8.6d allows remote attackers to execute arbitrary code via crafted arguments to the (1) addTarget, (2) getVariable, or (3) setVariable function, resulting from a "bad initialized pointer," aka a "recursive plugin release vulnerability."

Scoring

CVSS6.8 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS11.12% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploityes
Published2007-12-06
Last modified2026-06-16

Affected (1)

VendorProduct
videolanvlc media player

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD