VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data
ID: f8fe7e10-9904-502f-a4c9-29bb69be0d48
STIX ID: report--f8fe7e10-9904-502f-a4c9-29bb69be0d48
Feed Name: Cyber Press
**VLC vulnerabilities:** Two flaws (CVE-2026-56711 — heap out-of-bounds write, CVSS v4 8.6; CVE-2026-73324 — heap out-of-bounds read, CVSS v4 6.9) affect VLC Media Player 3.0.0–3.0.23: a crafted PNG or playlist can trigger a heap overflow during picture allocation allowing crashes or possible code execution, and a long RealRTSP Session header can cause memory disclosure that may be exfiltrated to an attacker-controlled RTSP server; users should avoid untrusted files/links and apply vendor updates when available.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
