VideoLAN VLC media player 2.2.x is prone to a use after free vulnerability which an attacker can leverage to execute arbitrary code via crafted MKV files. Failed exploit attempts will likely result in denial of service conditions.
https://www.exploit-db.com/exploits/45626/
https://www.debian.org/security/2018/dsa-4251