9.3

CVE-2008-1686

Array index vulnerability in Speex 1.1.12 and earlier, as used in libfishsound 0.9.0 and earlier, including Illiminable DirectShow Filters and Annodex Plugins for Firefox, xine-lib before 1.1.12, and many other products, allows remote attackers to execute arbitrary code via a header structure containing a negative offset, which is used to dereference a function pointer.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
XineXine-lib Version <= 1.1.11.1
XineXine-lib Version0.9.8
XineXine-lib Version0.9.13
XineXine-lib Version0.99
XineXine-lib Version1.0
XineXine-lib Version1.0.1
XineXine-lib Version1.0.2
XineXine-lib Version1.0.3a
XineXine-lib Version1.1.0
XineXine-lib Version1.1.1
XineXine-lib Version1.1.10
XineXine-lib Version1.1.10.1
XineXine-lib Version1.1.11
XiphSpeex Version <= 1.1.12
XiphSpeex Version1.0.2
XiphSpeex Version1.0.3
XiphSpeex Version1.0.4
XiphSpeex Version1.0.5
XiphSpeex Version1.1.1
XiphSpeex Version1.1.2
XiphSpeex Version1.1.3
XiphSpeex Version1.1.4
XiphSpeex Version1.1.5
XiphSpeex Version1.1.6
XiphSpeex Version1.1.7
XiphSpeex Version1.1.8
XiphSpeex Version1.1.9
XiphSpeex Version1.1.10
XiphSpeex Version1.1.11
XiphSpeex Version1.1.11.1
XiphLibfishsound Version <= 0.9.0
XiphLibfishsound Version0.5.41
XiphLibfishsound Version0.5.42
XiphLibfishsound Version0.6.0
XiphLibfishsound Version0.6.1
XiphLibfishsound Version0.6.2
XiphLibfishsound Version0.6.3
XiphLibfishsound Version0.7.0
XiphLibfishsound Version0.8.0
XiphLibfishsound Version0.8.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 5.25% 0.896
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C