← Back

CVE-2010-1443

nvd nist
Published: Dec 26, 2014Modified: May 6, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:N/I:N/A:P
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

The parse_track_node function in modules/demux/playlist/xspf.c in the XSPF playlist parser in VideoLAN VLC media player before 1.0.6 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an empty location element in an XML Shareable Playlist Format (XSPF) document.

Affected (44)

1 product
Vlc Media Player
Configuration A
44 vulnerable
Vulnerable SoftwareAffected Versions
Videolan
Up to 1.0.5
Version 0.5.0
Version 0.5.1
Version 0.5.2
Version 0.5.3
Version 0.6.0
Version 0.6.1
Version 0.6.2
Version 0.7.0
Version 0.7.1
Version 0.7.2
Version 0.8.0
Version 0.8.1337
Version 0.8.1
Version 0.8.2
Version 0.8.4
Version 0.8.4a
Version 0.8.5
Version 0.8.6
Version 0.8.6a
Version 0.8.6b
Version 0.8.6c
Version 0.8.6d
Version 0.8.6e
Version 0.8.6f
Version 0.8.6g
Version 0.8.6h
Version 0.8.6i
Version 0.9.0
Version 0.9.10
Version 0.9.1
Version 0.9.2
Version 0.9.3
Version 0.9.4
Version 0.9.5
Version 0.9.6
Version 0.9.8a
Version 0.9.9
Version 0.9.9a
Version 1.0.0
Version 1.0.1
Version 1.0.2
Version 1.0.3
Version 1.0.4

Timeline

No history available yet.