Vulnerabilities > Xine

DATE CVE VULNERABILITY TITLE RISK
2008-04-08 CVE-2008-1686 Numeric Errors vulnerability in multiple products
Array index vulnerability in Speex 1.1.12 and earlier, as used in libfishsound 0.9.0 and earlier, including Illiminable DirectShow Filters and Annodex Plugins for Firefox, xine-lib before 1.1.12, and many other products, allows remote attackers to execute arbitrary code via a header structure containing a negative offset, which is used to dereference a function pointer.
network
xine xiph CWE-189
critical
9.3
2008-03-24 CVE-2008-1482 Buffer Errors vulnerability in Xine Xine-Lib 1.1.11
Multiple integer overflows in xine-lib 1.1.11 and earlier allow remote attackers to trigger heap-based buffer overflows and possibly execute arbitrary code via (1) a crafted .FLV file, which triggers an overflow in demuxers/demux_flv.c; (2) a crafted .MOV file, which triggers an overflow in demuxers/demux_qt.c; (3) a crafted .RM file, which triggers an overflow in demuxers/demux_real.c; (4) a crafted .MVE file, which triggers an overflow in demuxers/demux_wc3movie.c; (5) a crafted .MKV file, which triggers an overflow in demuxers/ebml.c; or (6) a crafted .CAK file, which triggers an overflow in demuxers/demux_film.c.
network
xine CWE-119
6.8
2008-03-24 CVE-2008-0073 Numeric Errors vulnerability in Xine Xine-Lib 1.1.10.1
Array index error in the sdpplin_parse function in input/libreal/sdpplin.c in xine-lib 1.1.10.1 allows remote RTSP servers to execute arbitrary code via a large streamid SDP parameter.
network
redhat xine CWE-189
6.8
2008-02-05 CVE-2008-0486 Numeric Errors vulnerability in multiple products
Array index vulnerability in libmpdemux/demux_audio.c in MPlayer 1.0rc2 and SVN before r25917, and possibly earlier versions, as used in Xine-lib 1.1.10, might allow remote attackers to execute arbitrary code via a crafted FLAC tag, which triggers a buffer overflow.
network
low complexity
mplayer xine CWE-189
7.5
2008-01-11 CVE-2008-0238 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Xine Xine-Lib
Multiple heap-based buffer overflows in the rmff_dump_cont function in input/libreal/rmff.c in xine-lib 1.1.9 allow remote attackers to execute arbitrary code via the SDP (1) Title, (2) Author, or (3) Copyright attribute, related to the rmff_dump_header function, different vectors than CVE-2008-0225.
network
low complexity
xine CWE-119
7.5
2008-01-10 CVE-2008-0225 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Xine Xine-Lib
Heap-based buffer overflow in the rmff_dump_cont function in input/libreal/rmff.c in xine-lib 1.1.9 and earlier allows remote attackers to execute arbitrary code via the SDP Abstract attribute in an RTSP session, related to the rmff_dump_header function and related to disregarding the max field.
network
low complexity
xine CWE-119
6.4
2007-01-16 CVE-2007-0255 Remote Format String vulnerability in Xine 0.99.4
XINE 0.99.4 allows user-assisted remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a certain M3U file that contains a long #EXTINF line and contains format string specifiers in an invalid udp:// URI, possibly a variant of CVE-2007-0017.
network
xine
critical
9.3
2007-01-16 CVE-2007-0254 Remote Format String vulnerability in Xine Errors.C
Format string vulnerability in the errors_create_window function in errors.c in xine-ui allows attackers to execute arbitrary code via unknown vectors.
network
low complexity
xine
critical
10.0
2006-11-30 CVE-2006-6172 Remote Buffer Overflow vulnerability in Xine-Lib RuleMatches
Buffer overflow in the asmrp_eval function in the RealMedia RTSP stream handler (asmrp.c) for Real Media input plugin, as used in (1) xine/xine-lib, (2) MPlayer 1.0rc1 and earlier, and possibly others, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a rulebook with a large number of rulematches.
network
low complexity
mplayer xine
7.5
2006-09-14 CVE-2006-4799 Unspecified vulnerability in Xine Xine-Lib 1.0.1/1.0.2/1.1.0
Buffer overflow in ffmpeg for xine-lib before 1.1.2 might allow context-dependent attackers to execute arbitrary code via a crafted AVI file and "bad indexes", a different vulnerability than CVE-2005-4048 and CVE-2006-2802.
network
low complexity
xine
7.5