Loading
A heap-based buffer over-read exists in DemuxInit() in demux/asf/asf.c in VideoLAN VLC media player 3.0.7.1 via a crafted .mkv file.
Use CWE-125, Videolan vendor hub and Vlc Media Player product page to widen CVE-2019-14776 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2023-47359, CVE-2023-46814 and CVE-2022-41325 for nearby disclosures in the same product family.