Xine

Xine-lib

38 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.29%
  • Veröffentlicht 26.11.2008 01:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

xine-lib before 1.1.15 performs V4L video frame preallocation before ascertaining the required length, which has unknown impact and attack vectors, possibly related to a buffer overflow in the open_video_capture_device function in src/input/input_v4l...

  • EPSS 4.35%
  • Veröffentlicht 26.11.2008 01:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Multiple heap-based buffer overflows in xine-lib before 1.1.15 allow remote attackers to execute arbitrary code via vectors that send ID3 data to the (1) id3v22_interp_frame and (2) id3v24_interp_frame functions in src/demuxers/id3.c. NOTE: the prov...

  • EPSS 1.04%
  • Veröffentlicht 26.11.2008 01:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The real_parse_audio_specific_data function in demux_real.c in xine-lib 1.1.12, and other 1.1.15 and earlier versions, uses an untrusted height (aka codec_data_length) value as a divisor, which allow remote attackers to cause a denial of service (div...

  • EPSS 0.56%
  • Veröffentlicht 26.11.2008 01:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

xine-lib before 1.1.15 allows remote attackers to cause a denial of service (crash) via "MP3 files with metadata consisting only of separators."

Exploit
  • EPSS 2.03%
  • Veröffentlicht 18.07.2008 16:41:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

xine-lib before 1.1.15 allows remote attackers to cause a denial of service (crash) via a crafted OGG file, as demonstrated by playing lol-ffplay.ogg with xine.

  • EPSS 7.93%
  • Veröffentlicht 17.04.2008 22:05:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Stack-based buffer overflow in the demux_nsf_send_chunk function in src/demuxers/demux_nsf.c in xine-lib 1.1.12 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long NSF title.

  • EPSS 5.25%
  • Veröffentlicht 08.04.2008 18:05:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Array index vulnerability in Speex 1.1.12 and earlier, as used in libfishsound 0.9.0 and earlier, including Illiminable DirectShow Filters and Annodex Plugins for Firefox, xine-lib before 1.1.12, and many other products, allows remote attackers to ex...

  • EPSS 1.59%
  • Veröffentlicht 24.03.2008 22:44:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Array index error in the sdpplin_parse function in input/libreal/sdpplin.c in xine-lib 1.1.10.1 allows remote RTSP servers to execute arbitrary code via a large streamid SDP parameter.

Exploit
  • EPSS 2.12%
  • Veröffentlicht 24.03.2008 22:44:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Multiple integer overflows in xine-lib 1.1.11 and earlier allow remote attackers to trigger heap-based buffer overflows and possibly execute arbitrary code via (1) a crafted .FLV file, which triggers an overflow in demuxers/demux_flv.c; (2) a crafted...

  • EPSS 6.11%
  • Veröffentlicht 29.02.2008 19:44:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Buffer overflow in demuxers/demux_asf.c (aka the ASF demuxer) in the xineplug_dmx_asf.so plugin in xine-lib before 1.1.10 allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a crafted ASF header. NOTE: this iss...