Show filters
28 Total Results
Displaying 21-28 of 28
Sort by:
Attacker Value
Unknown

CVE-2008-1423

Disclosure Date: May 16, 2008 (last updated October 04, 2023)
Integer overflow in a certain quantvals and quantlist calculation in Xiph.org libvorbis 1.2.0 and earlier allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted OGG file with a large virtual space for its codebook, which triggers a heap overflow.
0
Attacker Value
Unknown

CVE-2008-1419

Disclosure Date: May 16, 2008 (last updated October 04, 2023)
Xiph.org libvorbis 1.2.0 and earlier does not properly handle a zero value for codebook.dim, which allows remote attackers to cause a denial of service (crash or infinite loop) or trigger an integer overflow.
0
Attacker Value
Unknown

CVE-2008-2009

Disclosure Date: May 16, 2008 (last updated October 04, 2023)
Xiph.org libvorbis before 1.0 does not properly check for underpopulated Huffman trees, which allows remote attackers to cause a denial of service (crash) via a crafted OGG file that triggers memory corruption during execution of the _make_decode_tree function.
0
Attacker Value
Unknown

CVE-2008-1420

Disclosure Date: May 16, 2008 (last updated October 04, 2023)
Integer overflow in residue partition value (aka partvals) evaluation in Xiph.org libvorbis 1.2.0 and earlier allows remote attackers to execute arbitrary code via a crafted OGG file, which triggers a heap overflow.
0
Attacker Value
Unknown

CVE-2008-1686

Disclosure Date: April 08, 2008 (last updated October 04, 2023)
Array index vulnerability in Speex 1.1.12 and earlier, as used in libfishsound 0.9.0 and earlier, including Illiminable DirectShow Filters and Annodex Plugins for Firefox, xine-lib before 1.1.12, and many other products, allows remote attackers to execute arbitrary code via a header structure containing a negative offset, which is used to dereference a function pointer.
0
Attacker Value
Unknown

CVE-2007-4066

Disclosure Date: September 21, 2007 (last updated October 04, 2023)
Multiple buffer overflows in Xiph.Org libvorbis before 1.2.0 allow context-dependent attackers to cause a denial of service or have other unspecified impact via a crafted OGG file, aka trac Changesets 13162, 13168, 13169, 13170, 13172, 13211, and 13215, as demonstrated by an overflow in oggenc.exe related to the _psy_noiseguards_8 array.
0
Attacker Value
Unknown

CVE-2007-4065

Disclosure Date: September 21, 2007 (last updated October 04, 2023)
lib/vorbisfile.c in libvorbisfile in Xiph.Org libvorbis before 1.2.0 allows context-dependent attackers to cause a denial of service (infinite loop) via a crafted OGG file, aka trac Changeset 13217.
0
Attacker Value
Unknown

CVE-2007-1344

Disclosure Date: March 08, 2007 (last updated October 04, 2023)
Multiple buffer overflows in src/ezstream.c in Ezstream before 0.3.0 allow remote attackers to execute arbitrary code via a crafted XML configuration file processed by the (1) urlParse function, which causes a stack-based overflow and the (2) ReplaceString function, which causes a heap-based overflow. NOTE: some of these details are obtained from third party information.
0