Loading
The MP4_ReadBox_String function in modules/demux/mp4/libmp4.c in VideoLAN VLC media player before 2.1.6 performs an incorrect cast operation from a 64-bit integer to a 32-bit integer, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a large box size.
Use CWE-704, Videolan vendor hub and Vlc Media Player product page to widen CVE-2014-9627 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2023-47359, CVE-2023-46814 and CVE-2022-41325 for nearby disclosures in the same product family.