CVE-2008-5245
- EPSS 1.29%
- Veröffentlicht 26.11.2008 01:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
xine-lib before 1.1.15 performs V4L video frame preallocation before ascertaining the required length, which has unknown impact and attack vectors, possibly related to a buffer overflow in the open_video_capture_device function in src/input/input_v4l...
CVE-2008-5246
- EPSS 4.35%
- Veröffentlicht 26.11.2008 01:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple heap-based buffer overflows in xine-lib before 1.1.15 allow remote attackers to execute arbitrary code via vectors that send ID3 data to the (1) id3v22_interp_frame and (2) id3v24_interp_frame functions in src/demuxers/id3.c. NOTE: the prov...
CVE-2008-5247
- EPSS 1.04%
- Veröffentlicht 26.11.2008 01:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The real_parse_audio_specific_data function in demux_real.c in xine-lib 1.1.12, and other 1.1.15 and earlier versions, uses an untrusted height (aka codec_data_length) value as a divisor, which allow remote attackers to cause a denial of service (div...
CVE-2008-5248
- EPSS 0.56%
- Veröffentlicht 26.11.2008 01:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
xine-lib before 1.1.15 allows remote attackers to cause a denial of service (crash) via "MP3 files with metadata consisting only of separators."
CVE-2008-3231
- EPSS 2.03%
- Veröffentlicht 18.07.2008 16:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
xine-lib before 1.1.15 allows remote attackers to cause a denial of service (crash) via a crafted OGG file, as demonstrated by playing lol-ffplay.ogg with xine.
CVE-2008-1878
- EPSS 7.93%
- Veröffentlicht 17.04.2008 22:05:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Stack-based buffer overflow in the demux_nsf_send_chunk function in src/demuxers/demux_nsf.c in xine-lib 1.1.12 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long NSF title.
CVE-2008-1686
- EPSS 5.25%
- Veröffentlicht 08.04.2008 18:05:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Array index vulnerability in Speex 1.1.12 and earlier, as used in libfishsound 0.9.0 and earlier, including Illiminable DirectShow Filters and Annodex Plugins for Firefox, xine-lib before 1.1.12, and many other products, allows remote attackers to ex...
CVE-2008-0073
- EPSS 1.59%
- Veröffentlicht 24.03.2008 22:44:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Array index error in the sdpplin_parse function in input/libreal/sdpplin.c in xine-lib 1.1.10.1 allows remote RTSP servers to execute arbitrary code via a large streamid SDP parameter.
CVE-2008-1482
- EPSS 2.12%
- Veröffentlicht 24.03.2008 22:44:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple integer overflows in xine-lib 1.1.11 and earlier allow remote attackers to trigger heap-based buffer overflows and possibly execute arbitrary code via (1) a crafted .FLV file, which triggers an overflow in demuxers/demux_flv.c; (2) a crafted...
CVE-2008-1110
- EPSS 6.11%
- Veröffentlicht 29.02.2008 19:44:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Buffer overflow in demuxers/demux_asf.c (aka the ASF demuxer) in the xineplug_dmx_asf.so plugin in xine-lib before 1.1.10 allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a crafted ASF header. NOTE: this iss...