CVE-2008-5235
- EPSS 3.48%
- Veröffentlicht 26.11.2008 01:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Heap-based buffer overflow in the demux_real_send_chunk function in src/demuxers/demux_real.c in xine-lib before 1.1.15 allows remote attackers to execute arbitrary code via a crafted Real Media file. NOTE: some of these details are obtained from thi...
CVE-2008-5236
- EPSS 5.52%
- Veröffentlicht 26.11.2008 01:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple heap-based buffer overflows in xine-lib 1.1.12, and other 1.1.15 and earlier versions, allow remote attackers to execute arbitrary code via vectors related to (1) a crafted EBML element length processed by the parse_block_group function in d...
- EPSS 5.76%
- Veröffentlicht 26.11.2008 01:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple integer overflows in xine-lib 1.1.12, and other 1.1.15 and earlier versions, allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via (1) crafted width and height values that are not validated by the...
CVE-2008-5238
- EPSS 3.16%
- Veröffentlicht 26.11.2008 01:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Integer overflow in the real_parse_mdpr function in demux_real.c in xine-lib 1.1.12, and other versions before 1.1.15, allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted stream_name_size fiel...
CVE-2007-0255
- EPSS 2.49%
- Veröffentlicht 16.01.2007 23:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
XINE 0.99.4 allows user-assisted remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a certain M3U file that contains a long #EXTINF line and contains format string specifiers in an invalid udp://...
- EPSS 1.2%
- Veröffentlicht 05.05.2006 19:02:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Multiple format string vulnerabilities in xiTK (xitk/main.c) in xine 0.99.4 might allow attackers to cause a denial of service via format string specifiers in an MP3 filename specified on the command line. NOTE: this is a different vulnerability than...
CVE-2006-1905
- EPSS 7.96%
- Veröffentlicht 20.04.2006 10:02:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Multiple format string vulnerabilities in xiTK (xitk/main.c) in xine 0.99.3 allow remote attackers to execute arbitrary code via format string specifiers in a long filename on an EXTINFO line in a playlist file.
- EPSS 5.7%
- Veröffentlicht 10.01.2005 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Heap-based buffer overflow in the pnm_get_chunk function for xine 0.99.2, and other packages such as MPlayer that use the same code, allows remote attackers to execute arbitrary code via long PNA_TAG values, a different vulnerability than CVE-2004-11...
- EPSS 0.5%
- Veröffentlicht 10.01.2005 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
The pnm_get_chunk function in xine 0.99.2 and earlier, and other packages such as MPlayer that use the same code, does not properly verify that the chunk size is less than the PREAMBLE_SIZE, which causes a read operation with a negative length that l...
CVE-2004-1475
- EPSS 5.48%
- Veröffentlicht 31.12.2004 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Multiple stack-based buffer overflows in xine-lib 1-rc2 through 1-rc5 allow attackers to execute arbitrary code via (1) long VideoCD vcd:// MRLs or (2) long subtitle lines.