Описание
A local, authenticated attacker can bypass the passcode in the VideoLAN VLC media player app before 3.1.5 for iOS by opening a URL and turning the phone.
Ссылки
- PatchThird Party Advisory
- ProductThird Party Advisory
- PatchThird Party Advisory
- ProductThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 3.1.5 (исключая)
cpe:2.3:a:videolan:vlc_for_mobile:*:*:*:*:*:iphone_os:*:*
EPSS
Процентиль: 11%
0.00039
Низкий
6.6 Medium
CVSS3
6.6 Medium
CVSS3
4.6 Medium
CVSS2
Дефекты
CWE-287
CWE-287
Связанные уязвимости
CVSS3: 6.6
github
больше 3 лет назад
A local, authenticated attacker can bypass the passcode in the VideoLAN VLC media player app before 3.1.5 for iOS by opening a URL and turning the phone.
EPSS
Процентиль: 11%
0.00039
Низкий
6.6 Medium
CVSS3
6.6 Medium
CVSS3
4.6 Medium
CVSS2
Дефекты
CWE-287
CWE-287