VideoLAN has this to say about the latest VLC release
We are pleased to announce the release of VLC media player 0.8.6f. This is a bugfix release. VLC media player 0.8.6e and earlier versions suffer from security vulnerabilities in the Subtitle demuxer, Real RTSP demuxer, MP4 demuxer and Cinepak codec.
This release also includes improved video output on multi-screen setups running Mac OS X and compatibility with Windows 9x/ME has been restored. We strongly recommend all users to update to this new version.
VLC media player is free and supports a large number of multimedia formats. Even with Quicktime Pro,with the MPEG-2 codec, can not play most avi files. As mentioned before, do not be dissuaded by the version number, this software has performed as a final release for a number of years.