Show filters
67 Total Results
Displaying 51-60 of 67
Sort by:
Attacker Value
Unknown

CVE-2007-1136

Disclosure Date: March 02, 2007 (last updated October 04, 2023)
index.php in WebMplayer before 0.6.1-Alpha allows remote attackers to execute arbitrary code via shell metacharacters in an exec function call. NOTE: some sources have referred to this as eval injection in the param parameter, but CVE source inspection suggests that this is erroneous.
0
Attacker Value
Unknown

CVE-2007-1135

Disclosure Date: March 02, 2007 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in WebMplayer before 0.6.1-Alpha allow remote attackers to execute arbitrary SQL commands via the (1) strid parameter to index.php and the (2) id[0] or other id array index parameter to filecheck.php.
0
Attacker Value
Unknown

CVE-2006-6172

Disclosure Date: November 30, 2006 (last updated October 04, 2023)
Buffer overflow in the asmrp_eval function in the RealMedia RTSP stream handler (asmrp.c) for Real Media input plugin, as used in (1) xine/xine-lib, (2) MPlayer 1.0rc1 and earlier, and possibly others, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a rulebook with a large number of rulematches.
0
Attacker Value
Unknown

CVE-2006-1502

Disclosure Date: March 30, 2006 (last updated February 22, 2025)
Multiple integer overflows in MPlayer 1.0pre7try2 allow remote attackers to cause a denial of service and trigger heap-based buffer overflows via (1) a certain ASF file handled by asfheader.c that causes the asf_descrambling function to be passed a negative integer after the conversion from a char to an int or (2) an AVI file with a crafted wLongsPerEntry or nEntriesInUse value in the indx chunk, which is handled in aviheader.c.
0
Attacker Value
Unknown

CVE-2006-0579

Disclosure Date: February 08, 2006 (last updated February 22, 2025)
Multiple integer overflows in (1) the new_demux_packet function in demuxer.h and (2) the demux_asf_read_packet function in demux_asf.c in MPlayer 1.0pre7try2 and earlier allow remote attackers to execute arbitrary code via an ASF file with a large packet length value. NOTE: the provenance of this information is unknown; portions of the details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2005-2718

Disclosure Date: August 29, 2005 (last updated February 22, 2025)
Buffer overflow in ad_pcm.c in MPlayer 1.0pre7 and earlier allows remote attackers to execute arbitrary code via crafted PCM audio data, as demonstrated using a video file with an audio header containing a large value in a stream format (strf) chunk.
0
Attacker Value
Unknown

CVE-2005-1195

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Multiple heap-based buffer overflows in the code used to handle (1) MMS over TCP (MMST) streams or (2) RealMedia RTSP streams in xine-lib before 1.0, and other products that use xine-lib such as MPlayer 1.0pre6 and earlier, allow remote malicious servers to execute arbitrary code.
0
Attacker Value
Unknown

CVE-2004-1309

Disclosure Date: January 10, 2005 (last updated February 22, 2025)
Heap-based buffer overflow in the demux_open_bmp function in demux_bmp.c for Unix MPlayer 1.0pre5 allows remote attackers to execute arbitrary code via a bitmap (BMP) file containing a large biClrUsed field.
0
Attacker Value
Unknown

CVE-2004-1187

Disclosure Date: January 10, 2005 (last updated February 22, 2025)
Heap-based buffer overflow in the pnm_get_chunk function for xine 0.99.2, and other packages such as MPlayer that use the same code, allows remote attackers to execute arbitrary code via long PNA_TAG values, a different vulnerability than CVE-2004-1188.
0
Attacker Value
Unknown

CVE-2004-1310

Disclosure Date: January 10, 2005 (last updated February 22, 2025)
Stack-based buffer overflow in the asf_mmst_streaming.c functionality for MPlayer 1.0pre5 allows remote attackers to execute arbitrary code via a large MMST stream packet.
0