Vulnerabilities > Mplayer > Mplayer > 0.91

DATE CVE VULNERABILITY TITLE RISK
2008-12-17 CVE-2008-5616 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Mplayer
Stack-based buffer overflow in the demux_open_vqf function in libmpdemux/demux_vqf.c in MPlayer 1.0 rc2 before r28150 allows remote attackers to execute arbitrary code via a malformed TwinVQ file.
network
low complexity
mplayer CWE-119
critical
10.0
2008-10-20 CVE-2008-4610 Resource Management Errors vulnerability in Mplayer
MPlayer allows remote attackers to cause a denial of service (application crash) via (1) a malformed AAC file, as demonstrated by lol-vlc.aac; or (2) a malformed Ogg Media (OGM) file, as demonstrated by lol-ffplay.ogm, different vectors than CVE-2007-6718.
network
low complexity
mplayer CWE-399
5.0
2008-10-20 CVE-2007-6718 Denial-Of-Service vulnerability in MPlayer
MPlayer, possibly 1.0rc1, allows remote attackers to cause a denial of service (SIGSEGV and application crash) via (1) a malformed MP3 file, as demonstrated by lol-mplayer.mp3; (2) a malformed Ogg Vorbis file, as demonstrated by lol-mplayer.ogg; (3) a malformed MPEG-1 file, as demonstrated by lol-mplayer.mpg; (4) a malformed MPEG-2 file, as demonstrated by lol-mplayer.m2v; (5) a malformed MPEG-4 AVI file, as demonstrated by lol-mplayer.avi; (6) a malformed FLAC file, as demonstrated by lol-mplayer.flac; (7) a malformed Ogg Theora file, as demonstrated by lol-mplayer.ogm; (8) a malformed WMV file, as demonstrated by lol-mplayer.wmv; or (9) a malformed AAC file, as demonstrated by lol-mplayer.aac.
network
mplayer
4.3
2008-09-29 CVE-2008-3827 Numeric Errors vulnerability in Mplayer
Multiple integer underflows in the Real demuxer (demux_real.c) in MPlayer 1.0_rc2 and earlier allow remote attackers to cause a denial of service (process termination) and possibly execute arbitrary code via a crafted video file that causes the stream_read function to read or write arbitrary memory.
network
mplayer CWE-189
critical
9.3
2005-01-10 CVE-2004-1285 Remote Security vulnerability in MPlayer
Buffer overflow in the get_header function in asf_mmst_streaming.c for MPlayer 1.0pre5 allows remote attackers to execute arbitrary code via a crafted ASF video stream.
network
low complexity
mplayer
critical
10.0
2005-01-10 CVE-2004-1188 The pnm_get_chunk function in xine 0.99.2 and earlier, and other packages such as MPlayer that use the same code, does not properly verify that the chunk size is less than the PREAMBLE_SIZE, which causes a read operation with a negative length that leads to a buffer overflow via (1) RMF_TAG, (2) DATA_TAG, (3) PROP_TAG, (4) MDPR_TAG, and (5) CONT_TAG values, a different vulnerability than CVE-2004-1187.
network
low complexity
mplayer xine mandrakesoft
critical
10.0
2005-01-10 CVE-2004-1187 Heap-based buffer overflow in the pnm_get_chunk function for xine 0.99.2, and other packages such as MPlayer that use the same code, allows remote attackers to execute arbitrary code via long PNA_TAG values, a different vulnerability than CVE-2004-1188.
network
low complexity
mplayer xine mandrakesoft
critical
10.0
2004-08-06 CVE-2004-0659 Buffer Overflow vulnerability in MPlayer GUI File Name
Buffer overflow in TranslateFilename for common.c in MPlayer 1.0pre4 allows remote attackers to execute arbitrary code via a long file name.
network
low complexity
mplayer
critical
10.0
2004-05-04 CVE-2004-0386 Remote HTTP Header Buffer Overflow vulnerability in MPlayer
Buffer overflow in the HTTP parser for MPlayer 1.0pre3 and earlier, 0.90, and 0.91 allows remote attackers to execute arbitrary code via a long Location header.
network
low complexity
mplayer gentoo mandrakesoft
critical
10.0
2003-11-17 CVE-2003-0835 Unspecified vulnerability in Mplayer
Multiple buffer overflows in asf_http_request of MPlayer before 0.92 allows remote attackers to execute arbitrary code via an ASX header with a long hostname.
network
low complexity
mplayer
7.5