Loading
Heap out-of-bound read in ParseJSS in VideoLAN VLC due to missing check of string length allows attackers to read heap uninitialized data via a crafted subtitles file.
Use CWE-125, Videolan vendor hub and Vlc Media Player product page to widen CVE-2017-8312 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2023-47359, CVE-2023-46814 and CVE-2022-41325 for nearby disclosures in the same product family.