Show filters
18 Total Results
Displaying 11-18 of 18
Sort by:
Attacker Value
Unknown
CVE-2008-5243
Disclosure Date: November 26, 2008 (last updated October 04, 2023)
The real_parse_headers function in demux_real.c in xine-lib 1.1.12, and other 1.1.15 and earlier versions, relies on an untrusted input length value to "reindex into an allocated buffer," which allows remote attackers to cause a denial of service (crash) via a crafted value, probably an array index error.
0
Attacker Value
Unknown
CVE-2008-5234
Disclosure Date: November 26, 2008 (last updated October 04, 2023)
Multiple heap-based buffer overflows in xine-lib 1.1.12, and other versions before 1.1.15, allow remote attackers to execute arbitrary code via vectors related to (1) a crafted metadata atom size processed by the parse_moov_atom function in demux_qt.c and (2) frame reading in the id3v23_interp_frame function in id3.c. NOTE: as of 20081122, it is possible that vector 1 has not been fixed in 1.1.15.
0
Attacker Value
Unknown
CVE-2008-3231
Disclosure Date: July 18, 2008 (last updated October 04, 2023)
xine-lib before 1.1.15 allows remote attackers to cause a denial of service (crash) via a crafted OGG file, as demonstrated by playing lol-ffplay.ogg with xine.
0
Attacker Value
Unknown
CVE-2008-1686
Disclosure Date: April 08, 2008 (last updated October 04, 2023)
Array index vulnerability in Speex 1.1.12 and earlier, as used in libfishsound 0.9.0 and earlier, including Illiminable DirectShow Filters and Annodex Plugins for Firefox, xine-lib before 1.1.12, and many other products, allows remote attackers to execute arbitrary code via a header structure containing a negative offset, which is used to dereference a function pointer.
0
Attacker Value
Unknown
CVE-2006-4799
Disclosure Date: September 14, 2006 (last updated October 04, 2023)
Buffer overflow in ffmpeg for xine-lib before 1.1.2 might allow context-dependent attackers to execute arbitrary code via a crafted AVI file and "bad indexes", a different vulnerability than CVE-2005-4048 and CVE-2006-2802.
0
Attacker Value
Unknown
CVE-2006-2802
Disclosure Date: June 03, 2006 (last updated October 04, 2023)
Buffer overflow in the HTTP Plugin (xineplug_inp_http.so) for xine-lib 1.1.1 allows remote attackers to cause a denial of service (application crash) via a long reply from an HTTP server, as demonstrated using gxine 0.5.6.
0
Attacker Value
Unknown
CVE-2006-1664
Disclosure Date: April 07, 2006 (last updated February 22, 2025)
Buffer overflow in xine_list_delete_current in libxine 1.14 and earlier, as distributed in xine-lib 1.1.1 and earlier, allows remote attackers to execute arbitrary code via a crafted MPEG stream.
0
Attacker Value
Unknown
CVE-2005-2967
Disclosure Date: October 14, 2005 (last updated February 22, 2025)
Format string vulnerability in input_cdda.c in xine-lib 1-beta through 1-beta 3, 1-rc, 1.0 through 1.0.2, and 1.1.1 allows remote servers to execute arbitrary code via format string specifiers in metadata in CDDB server responses when the victim plays a CD.
0