Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
CVE-2019-5459
See a problem?
Please try reporting it
to the source
first.
Source
https://nvd.nist.gov/vuln/detail/CVE-2019-5459
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-5459.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2019-5459
Downstream
DEBIAN-CVE-2019-5459
DSA-4459-1
UBUNTU-CVE-2019-5459
openSUSE-SU-2019:1840-1
openSUSE-SU-2019:1897-1
openSUSE-SU-2019:1909-1
openSUSE-SU-2019:2015-1
Related
openSUSE-SU-2019:1840-1
openSUSE-SU-2019:1897-1
openSUSE-SU-2019:1909-1
openSUSE-SU-2019:2015-1
Published
2019-07-30T21:15:12Z
Modified
2025-10-13T08:56:26.753075Z
Severity
7.1 (High)
CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
CVSS Calculator
Summary
[none]
Details
An Integer underflow in VLC Media Player versions < 3.0.7 leads to an out-of-band read.
References
http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00005.html
http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00037.html
http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00040.html
http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00081.html
https://hackerone.com/reports/502816
Affected packages
Git
/
github.com/videolan/vlc-3.0
Affected ranges
Type
GIT
Repo
https://github.com/videolan/vlc-3.0
Events
Introduced
0
Unknown introduced commit / All previous commits are affected
Fixed
86cee310996569c2ee419a457107141ac472536b
Affected versions
0.*
0.9.0
0.9.0-test0
0.9.0-test1
0.9.0-test2
0.9.0-test3
1.*
1.0.0-pre1
1.0.0-pre2
1.0.0-rc1
1.1.0-ff
1.1.0-pre1
1.2.0-pre1
1.3.0-git
2.*
2.1.0-git
2.2.0-git
3.*
3.0.0
3.0.0-1
3.0.0-2
3.0.0-git
3.0.0-rc1
3.0.0-rc2
3.0.0-rc3
3.0.0-rc4
3.0.0-rc5
3.0.0-rc6
3.0.0-rc7
3.0.0-rc8
3.0.0.1
3.0.1
3.0.2
3.0.3
3.0.3-1
3.0.4
3.0.5
3.0.5-1
3.0.5-2
3.0.6
Other
svn-trunk
CVE-2019-5459 - OSV