5.1

CVE-2004-1476

Stack-based buffer overflow in the VideoCD (VCD) code in xine-lib 1-rc2 through 1-rc5, as derived from libcdio, allows attackers to execute arbitrary code via a VideoCD with an unterminated disk label.

Data is provided by the National Vulnerability Database (NVD)
XineXine Version0.9.18
XineXine Version1_rc2
XineXine Version1_rc3
XineXine Version1_rc4
XineXine Version1_rc5
XineXine-lib Version0.99
XineXine-lib Version1_rc2
XineXine-lib Version1_rc3
XineXine-lib Version1_rc4
XineXine-lib Version1_rc5
SuseSuse Linux Version8.0
SuseSuse Linux Version8.1
SuseSuse Linux Version8.2 Editionpersonal
SuseSuse Linux Version9.0 Editionpersonal
SuseSuse Linux Version9.0 Editionx86_64
SuseSuse Linux Version9.1 Editionpersonal
SuseSuse Linux Version9.2 Editionpersonal
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 2.05% 0.822
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.1 4.9 6.4
AV:N/AC:H/Au:N/C:P/I:P/A:P