peter bassill · operator
$ cve CVE-2017-8311 JSON

CVE-2017-8311 EXPLOIT

7.8
HIGH · CVSS 3.0 · EPSS 8.8% (pctl 95)

Patch early

A public exploit exists.

Description

Potential heap based buffer overflow in ParseJSS in VideoLAN VLC before 2.2.5 due to skipping NULL terminator in an input string allows attackers to execute arbitrary code via a crafted subtitles file.

Scoring

CVSS7.8 (HIGH, v3.0)
VectorCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS8.84% — more likely to be exploited than 95% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploityes
Published2017-05-23
Last modified2026-06-17

Affected (1)

VendorProduct
videolanvlc media player

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD