boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Saturday, October 3, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2026-73324

VideoLAN VLC media player — VLC media player 3.0.0 through 3.0.23 information disclosure vulnerability
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   P   L   N   N    5.3   .0024   13.7     —
AFFECTED
  Product           Versions  Fixed
  VLC media player  3.0.0 –   —
TIMELINE
  Aug 11  Reserved by VulnCheck
  Sep 9   Published (CNA: VulnCheck)
  Sep 14  RESCORED — CVE-2026-73324 (VideoLAN VLC media player). CVSS 6.9 → 5.3 (NVD).
CWE-125, CWE-170 · CNA: VulnCheck · CVSS v4.0 · 4 references · NVD status: Deferred

Description

Certain VLC media player builds in versions 3.0.0 through 3.0.23 contain a memory-safety vulnerability reachable when processing media from an attacker-controlled network source. Exploitation requires user interaction and may disclose a limited, layout-dependent amount of VLC process memory. Exposure depends on build configuration.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
August 11, 2026ReservedReserved by VulnCheck
September 9, 2026PublishedPublished (CNA: VulnCheck)
September 14, 2026RESCOREDRESCORED — CVE-2026-73324 (VideoLAN VLC media player). CVSS 6.9 → 5.3 (NVD).

Affected

Affected products and packages — 1 row
VendorProduct / PackageEcosystemVersion introducedFixed
VideoLANVLC media player—3.0.0—

Weaknesses

CWE-125 · CWE-170

References (4)

Related

Authoritative record: CVE-2026-73324 at cve.org

Vendors: videolan

Weaknesses: CWE-125 · CWE-170

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-73324 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Saturday, October 3, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.