Back to Database
Status published
High
CVE-2017-8311
Potential heap based buffer overflow in ParseJSS in VideoLAN VLC...
Vulnerability Description
Potential heap based buffer overflow in ParseJSS in VideoLAN VLC before 2.2.5 due to skipping NULL terminator in an input string allows attackers to execute arbitrary code via a crafted subtitles file.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2017-8311
Credits & Attribution
No credits recorded in the NVD database.
References
More from VideoLAN
View All →CVE-2025-51602
mmstu.c in VideoLAN VLC media player before 3.0.22 allows an...
Medium
4.8
CVE-2024-1580
Integer overflow in VideoLAN dav1d
Medium
5.9
CVE-2017-8313
Heap out-of-bound read in ParseJSS in VideoLAN VLC before 2.2.5...
Medium
5.5
CVE-2017-8312
Heap out-of-bound read in ParseJSS in VideoLAN VLC due to...
Medium
5.5
CVE-2017-8310
Heap out-of-bound read in CreateHtmlSubtitle in VideoLAN VLC 2.2.x due...
Medium
5.5
Affected Vendor
VideoLAN
View all reports →Affected Software
VLC
Vulnerable Versions:
<2.2.5
Timeline
Official Publish:
May 23rd, 2017
Last Modified:
August 5th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.