VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data
ID: bb85cf4c-8647-5049-9175-b24fb0d07400
STIX ID: report--bb85cf4c-8647-5049-9175-b24fb0d07400
Feed Name: GBHackers
**Two VLC vulnerabilities (versions 3.0.0–3.0.23): CVE-2026-56711 is a high-severity (CVSS 8.6) integer overflow in picture buffer allocation that can cause heap out‑of‑bounds writes when processing crafted PNG files (potential remote code execution), and CVE-2026-73324 is a medium-severity (CVSS 6.9) out‑of‑bounds read in RealRTSP response handling that can disclose heap memory to a malicious RTSP server; users should avoid opening untrusted images or RealRTSP playlists and apply vendor fixes when available.**
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
