While CVE CVE-2019-13602 & CVE-2019-13962 mention a base score of 8.8 and 9.8 respectively, the VideoLAN team believes this severity is highly exagerated in our We have not seen exploits performing code execution through these vulnerabilities ASLR and DEP help reduce the likelyness of code execution, but may be bypassed. While these issues in themselves are most likely to just crash the player, we can't exclude that they could be combined to leak user informations or
If successful, a malicious third party could trigger either a crash of VLC or an arbitratry code execution with the privileges of the target user.