CVE-2022-38860
- EPSS 0.04%
- Published 15.09.2022 15:15:10
- Last modified 21.11.2024 07:17:11
Certain The MPlayer Project products are vulnerable to Divide By Zero via function demux_open_avi() of libmpdemux/demux_avi.c which affects mencoder. This affects mplayer SVN-r38374-13.0.1 and mencoder SVN-r38374-13.0.1.
CVE-2022-38861
- EPSS 0.05%
- Published 15.09.2022 15:15:10
- Last modified 21.11.2024 07:17:11
The MPlayer Project mplayer SVN-r38374-13.0.1 is vulnerable to memory corruption via function free_mp_image() of libmpcodecs/mp_image.c.
CVE-2022-38863
- EPSS 0.04%
- Published 15.09.2022 15:15:10
- Last modified 21.11.2024 07:17:11
Certain The MPlayer Project products are vulnerable to Buffer Overflow via function mp_getbits() of libmpdemux/mpeg_hdr.c which affects mencoder and mplayer. This affects mecoder SVN-r38374-13.0.1 and mplayer SVN-r38374-13.0.1.
CVE-2022-38864
- EPSS 0.04%
- Published 15.09.2022 15:15:10
- Last modified 21.11.2024 07:17:11
Certain The MPlayer Project products are vulnerable to Buffer Overflow via the function mp_unescape03() of libmpdemux/mpeg_hdr.c. This affects mencoder SVN-r38374-13.0.1 and mplayer SVN-r38374-13.0.1.
CVE-2022-38865
- EPSS 0.04%
- Published 15.09.2022 15:15:10
- Last modified 21.11.2024 07:17:12
Certain The MPlayer Project products are vulnerable to Divide By Zero via the function demux_avi_read_packet of libmpdemux/demux_avi.c. This affects mplyer SVN-r38374-13.0.1 and mencoder SVN-r38374-13.0.1.
CVE-2022-38866
- EPSS 0.07%
- Published 15.09.2022 15:15:10
- Last modified 21.11.2024 07:17:12
Certain The MPlayer Project products are vulnerable to Buffer Overflow via read_avi_header() of libmpdemux/aviheader.c . This affects mplayer SVN-r38374-13.0.1 and mencoder SVN-r38374-13.0.1.
CVE-2018-25047
- EPSS 0.34%
- Published 15.09.2022 00:15:09
- Last modified 21.11.2024 04:03:26
In Smarty before 3.1.47 and 4.x before 4.2.1, libs/plugins/function.mailto.php allows XSS. A web page that uses smarty_function_mailto, and that could be parameterized using GET or POST input parameters, could allow injection of JavaScript code by a ...
CVE-2022-40674
- EPSS 0.91%
- Published 14.09.2022 11:15:54
- Last modified 30.05.2025 20:15:30
libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c.
CVE-2022-37797
- EPSS 0.32%
- Published 12.09.2022 15:15:08
- Last modified 21.11.2024 07:15:11
In lighttpd 1.4.65, mod_wstunnel does not initialize a handler function pointer if an invalid HTTP request (websocket handshake) is received. It leads to null pointer dereference which crashes the server. It could be used by an external attacker to c...
CVE-2022-38266
- EPSS 0.26%
- Published 09.09.2022 22:15:08
- Last modified 21.11.2024 07:16:08
An issue in the Leptonica linked library (v1.79.0) allows attackers to cause an arithmetic exception leading to a Denial of Service (DoS) via a crafted JPEG file.