Vulnerabilities > Divx

DATE CVE VULNERABILITY TITLE RISK
2015-01-13 CVE-2014-10024 Numeric Errors vulnerability in Divx Directshowdemuxfilter, Player and web Player
Multiple integer signedness errors in DirectShowDemuxFilter, as used in Divx Web Player, Divx Player, and other Divx plugins, allow remote attackers to execute arbitrary code via a (1) negative or (2) large value in a Stream Format (STRF) chunk in an AVI file, which triggers a heap-based buffer overflow.
network
low complexity
divx CWE-189
7.5
2012-09-07 CVE-2010-5232 Unspecified vulnerability in Divx Plus Player 8.1.0
Untrusted search path vulnerability in DivX Plus Player 8.1.0 allows local users to gain privileges via a Trojan horse ssleay32.dll file in a certain directory.
local
divx
6.9
2012-09-07 CVE-2010-5231 Unspecified vulnerability in Divx Player 7.2.0.19
Untrusted search path vulnerability in DivX Player 7.2.019 allows local users to gain privileges via a Trojan horse VersionCheckDLL.dll file in the current working directory, as demonstrated by a directory that contains a .avi file.
local
divx
6.9
2009-04-16 CVE-2008-5259 Numeric Errors vulnerability in Divx web Player
Integer signedness error in DivX Web Player 1.4.2.7, and possibly earlier versions, allows remote attackers to execute arbitrary code via a DivX file containing a crafted Stream Format (STRF) chunk, which triggers a heap-based buffer overflow.
network
divx CWE-189
critical
9.3
2008-04-22 CVE-2008-1912 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Divx Player
Stack-based buffer overflow in DivX Player 6.7 build 6.7.0.22 and earlier allows user-assisted remote attackers to cause a denial of service (application crash) or execute arbitrary code via a long subtitle in a .SRT file.
network
divx CWE-119
critical
9.3
2008-04-15 CVE-2008-1800 Cross-Site Scripting vulnerability in Divx Divxdb 0.94B
Multiple cross-site scripting (XSS) vulnerabilities in index.php in DivXDB 2002 0.94b allow remote attackers to inject arbitrary web script or HTML via the (1) choice, (2) _page_, (3) zone_admin, (4) general_search, and (5) import parameters.
network
divx CWE-79
4.3
2008-01-04 CVE-2008-0090 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products
A certain ActiveX control in npUpload.dll in DivX Player 6.6.0 allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long argument to the SetPassword method.
network
low complexity
divx microsoft CWE-119
5.0
2007-03-07 CVE-2007-1294 Remote Denial of Service vulnerability in Divx web Player 1.3.0
A certain ActiveX control in the DivXBrowserPlugin (npdivx32.dll) in DivX Web Player, as distributed with DivX Player 1.3.0, allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via large values to DivxWP.Resize, related to resizing images.
network
low complexity
divx
7.8
2007-01-23 CVE-2007-0429 Remote Denial of Service vulnerability in Divx Player 6.4.1
DivXBrowserPlugin (aka DivX Web Player) npdivx32.dll, as distributed with DivX Player 6.4.1, allows remote attackers to cause a denial of service (Internet Explorer 7 crash) by invoking the GoWindowed method for a certain instance of the ActiveX object.
network
low complexity
divx
5.0
2006-12-10 CVE-2006-6444 Buffer Overflow vulnerability in Divx Player 2.1/2.2.00.0
Stack-based buffer overflow in Nostra DivX Player 2.1, 2.2.00.0, and possibly earlier, allows remote attackers to execute arbitrary code via a long string in an M3U file.
network
divx
6.8