Show filters
61 Total Results
Displaying 31-40 of 61
Sort by:
Attacker Value
Unknown
CVE-2007-0406
Disclosure Date: January 23, 2007 (last updated October 04, 2023)
Multiple buffer overflows in the (1) main function in (a) client.c, and the (2) server_setup and (3) server_client_connect functions in (b) server.c in gxine 0.5.9 and earlier allow local users to cause a denial of service (daemon crash) or gain privileges via a long HOME environment variable. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2007-0255
Disclosure Date: January 16, 2007 (last updated October 04, 2023)
XINE 0.99.4 allows user-assisted remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a certain M3U file that contains a long #EXTINF line and contains format string specifiers in an invalid udp:// URI, possibly a variant of CVE-2007-0017.
0
Attacker Value
Unknown
CVE-2007-0254
Disclosure Date: January 16, 2007 (last updated October 04, 2023)
Format string vulnerability in the errors_create_window function in errors.c in xine-ui allows attackers to execute arbitrary code via unknown vectors.
0
Attacker Value
Unknown
CVE-2006-6172
Disclosure Date: November 30, 2006 (last updated October 04, 2023)
Buffer overflow in the asmrp_eval function in the RealMedia RTSP stream handler (asmrp.c) for Real Media input plugin, as used in (1) xine/xine-lib, (2) MPlayer 1.0rc1 and earlier, and possibly others, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a rulebook with a large number of rulematches.
0
Attacker Value
Unknown
CVE-2006-4799
Disclosure Date: September 14, 2006 (last updated October 04, 2023)
Buffer overflow in ffmpeg for xine-lib before 1.1.2 might allow context-dependent attackers to execute arbitrary code via a crafted AVI file and "bad indexes", a different vulnerability than CVE-2005-4048 and CVE-2006-2802.
0
Attacker Value
Unknown
CVE-2006-2200
Disclosure Date: June 28, 2006 (last updated October 04, 2023)
Stack-based buffer overflow in libmms, as used by (a) MiMMS 0.0.9 and (b) xine-lib 1.1.0 and earlier, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via the (1) send_command, (2) string_utf16, (3) get_data, and (4) get_media_packet functions, and possibly other functions.
0
Attacker Value
Unknown
CVE-2006-2802
Disclosure Date: June 03, 2006 (last updated October 04, 2023)
Buffer overflow in the HTTP Plugin (xineplug_inp_http.so) for xine-lib 1.1.1 allows remote attackers to cause a denial of service (application crash) via a long reply from an HTTP server, as demonstrated using gxine 0.5.6.
0
Attacker Value
Unknown
CVE-2006-2230
Disclosure Date: May 05, 2006 (last updated October 04, 2023)
Multiple format string vulnerabilities in xiTK (xitk/main.c) in xine 0.99.4 might allow attackers to cause a denial of service via format string specifiers in an MP3 filename specified on the command line. NOTE: this is a different vulnerability than CVE-2006-1905. In addition, if the only attack vectors involve a user-assisted, local command line argument of a non-setuid program, this issue might not be a vulnerability.
0
Attacker Value
Unknown
CVE-2006-1905
Disclosure Date: April 20, 2006 (last updated October 04, 2023)
Multiple format string vulnerabilities in xiTK (xitk/main.c) in xine 0.99.3 allow remote attackers to execute arbitrary code via format string specifiers in a long filename on an EXTINFO line in a playlist file.
0
Attacker Value
Unknown
CVE-2006-1664
Disclosure Date: April 07, 2006 (last updated February 22, 2025)
Buffer overflow in xine_list_delete_current in libxine 1.14 and earlier, as distributed in xine-lib 1.1.1 and earlier, allows remote attackers to execute arbitrary code via a crafted MPEG stream.
0