Vulnerabilities > Mplayer > Mplayer > 1.0.pre5

DATE CVE VULNERABILITY TITLE RISK
2008-12-17 CVE-2008-5616 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Mplayer
Stack-based buffer overflow in the demux_open_vqf function in libmpdemux/demux_vqf.c in MPlayer 1.0 rc2 before r28150 allows remote attackers to execute arbitrary code via a malformed TwinVQ file.
network
low complexity
mplayer CWE-119
critical
10.0
2008-10-20 CVE-2008-4610 Resource Management Errors vulnerability in Mplayer
MPlayer allows remote attackers to cause a denial of service (application crash) via (1) a malformed AAC file, as demonstrated by lol-vlc.aac; or (2) a malformed Ogg Media (OGM) file, as demonstrated by lol-ffplay.ogm, different vectors than CVE-2007-6718.
network
low complexity
mplayer CWE-399
5.0
2008-10-20 CVE-2007-6718 Denial-Of-Service vulnerability in MPlayer
MPlayer, possibly 1.0rc1, allows remote attackers to cause a denial of service (SIGSEGV and application crash) via (1) a malformed MP3 file, as demonstrated by lol-mplayer.mp3; (2) a malformed Ogg Vorbis file, as demonstrated by lol-mplayer.ogg; (3) a malformed MPEG-1 file, as demonstrated by lol-mplayer.mpg; (4) a malformed MPEG-2 file, as demonstrated by lol-mplayer.m2v; (5) a malformed MPEG-4 AVI file, as demonstrated by lol-mplayer.avi; (6) a malformed FLAC file, as demonstrated by lol-mplayer.flac; (7) a malformed Ogg Theora file, as demonstrated by lol-mplayer.ogm; (8) a malformed WMV file, as demonstrated by lol-mplayer.wmv; or (9) a malformed AAC file, as demonstrated by lol-mplayer.aac.
network
mplayer
4.3
2008-09-29 CVE-2008-3827 Numeric Errors vulnerability in Mplayer
Multiple integer underflows in the Real demuxer (demux_real.c) in MPlayer 1.0_rc2 and earlier allow remote attackers to cause a denial of service (process termination) and possibly execute arbitrary code via a crafted video file that causes the stream_read function to read or write arbitrary memory.
network
mplayer CWE-189
critical
9.3
2005-01-10 CVE-2004-1311 Denial-Of-Service vulnerability in Mplayer 1.0Pre5
Integer overflow in the real_setup_and_get_header function in real.c for Unix MPlayer 1.0pre5 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a Real RTSP streaming media file with a -1 content-length field, which leads to a heap-based buffer overflow.
network
low complexity
mplayer
critical
10.0
2005-01-10 CVE-2004-1310 Remote Security vulnerability in Mplayer 1.0Pre5
Stack-based buffer overflow in the asf_mmst_streaming.c functionality for MPlayer 1.0pre5 allows remote attackers to execute arbitrary code via a large MMST stream packet.
network
low complexity
mplayer
critical
10.0
2005-01-10 CVE-2004-1285 Remote Security vulnerability in MPlayer
Buffer overflow in the get_header function in asf_mmst_streaming.c for MPlayer 1.0pre5 allows remote attackers to execute arbitrary code via a crafted ASF video stream.
network
low complexity
mplayer
critical
10.0
2005-01-10 CVE-2004-1188 The pnm_get_chunk function in xine 0.99.2 and earlier, and other packages such as MPlayer that use the same code, does not properly verify that the chunk size is less than the PREAMBLE_SIZE, which causes a read operation with a negative length that leads to a buffer overflow via (1) RMF_TAG, (2) DATA_TAG, (3) PROP_TAG, (4) MDPR_TAG, and (5) CONT_TAG values, a different vulnerability than CVE-2004-1187.
network
low complexity
mplayer xine mandrakesoft
critical
10.0
2005-01-10 CVE-2004-1187 Heap-based buffer overflow in the pnm_get_chunk function for xine 0.99.2, and other packages such as MPlayer that use the same code, allows remote attackers to execute arbitrary code via long PNA_TAG values, a different vulnerability than CVE-2004-1188.
network
low complexity
mplayer xine mandrakesoft
critical
10.0