CVE-2019-14437: Out-of-bounds Read
Last updated 26 August 2025
Other sources
The xiphSplitHeaders function in modules/demux/xiph.h in VideoLAN VLC media player 3.0.7.1 does not check array bounds properly. As a result, a heap-based buffer over-read can be triggered via a crafted .ogg file.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2019-14437.
What is the affected software?
The affected software is VideoLAN VLC media player version 3.0.7.1.
What is the severity rating of CVE-2019-14437?
The severity rating of CVE-2019-14437 is high with a CVSS score of 7.8.
How can I fix the CVE-2019-14437 vulnerability?
To fix the CVE-2019-14437 vulnerability, update your VLC media player to version 3.0.8 or higher.
Where can I find more information about CVE-2019-14437?
You can find more information about CVE-2019-14437 at the following references: [Reference 1](http://git.videolan.org/?p=vlc.git&a=search&h=refs%2Fheads%2Fmaster&st=commit&s=cve-2019), [Reference 2](http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00036.html), [Reference 3](http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00046.html).