Vulnerabilities > Xine > Critical

DATE CVE VULNERABILITY TITLE RISK
2008-11-26 CVE-2008-5246 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Xine Xine-Lib
Multiple heap-based buffer overflows in xine-lib before 1.1.15 allow remote attackers to execute arbitrary code via vectors that send ID3 data to the (1) id3v22_interp_frame and (2) id3v24_interp_frame functions in src/demuxers/id3.c.
network
xine CWE-119
critical
9.3
2008-11-26 CVE-2008-5245 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Xine Xine-Lib
xine-lib before 1.1.15 performs V4L video frame preallocation before ascertaining the required length, which has unknown impact and attack vectors, possibly related to a buffer overflow in the open_video_capture_device function in src/input/input_v4l.c.
network
xine CWE-119
critical
9.3
2008-11-26 CVE-2008-5244 Remote Security vulnerability in xine-lib
Unspecified vulnerability in xine-lib before 1.1.15 has unknown impact and attack vectors related to libfaad.
network
low complexity
xine
critical
10.0
2008-11-26 CVE-2008-5237 Numeric Errors vulnerability in Xine
Multiple integer overflows in xine-lib 1.1.12, and other 1.1.15 and earlier versions, allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via (1) crafted width and height values that are not validated by the mymng_process_header function in demux_mng.c before use in an allocation calculation or (2) crafted current_atom_size and string_size values processed by the parse_reference_atom function in demux_qt.c for an RDRF_ATOM string.
network
low complexity
xine CWE-189
critical
10.0
2008-11-26 CVE-2008-5236 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Xine
Multiple heap-based buffer overflows in xine-lib 1.1.12, and other 1.1.15 and earlier versions, allow remote attackers to execute arbitrary code via vectors related to (1) a crafted EBML element length processed by the parse_block_group function in demux_matroska.c; (2) a certain combination of sps, w, and h values processed by the real_parse_audio_specific_data and demux_real_send_chunk functions in demux_real.c; and (3) an unspecified combination of three values processed by the open_ra_file function in demux_realaudio.c.
network
xine CWE-119
critical
9.3
2008-11-26 CVE-2008-5235 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Xine
Heap-based buffer overflow in the demux_real_send_chunk function in src/demuxers/demux_real.c in xine-lib before 1.1.15 allows remote attackers to execute arbitrary code via a crafted Real Media file.
network
xine CWE-119
critical
9.3
2008-11-26 CVE-2008-5234 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Xine Xine-Lib
Multiple heap-based buffer overflows in xine-lib 1.1.12, and other versions before 1.1.15, allow remote attackers to execute arbitrary code via vectors related to (1) a crafted metadata atom size processed by the parse_moov_atom function in demux_qt.c and (2) frame reading in the id3v23_interp_frame function in id3.c.
network
xine CWE-119
critical
9.3
2008-04-08 CVE-2008-1686 Numeric Errors vulnerability in multiple products
Array index vulnerability in Speex 1.1.12 and earlier, as used in libfishsound 0.9.0 and earlier, including Illiminable DirectShow Filters and Annodex Plugins for Firefox, xine-lib before 1.1.12, and many other products, allows remote attackers to execute arbitrary code via a header structure containing a negative offset, which is used to dereference a function pointer.
network
xine xiph CWE-189
critical
9.3
2007-01-16 CVE-2007-0255 Remote Format String vulnerability in Xine 0.99.4
XINE 0.99.4 allows user-assisted remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a certain M3U file that contains a long #EXTINF line and contains format string specifiers in an invalid udp:// URI, possibly a variant of CVE-2007-0017.
network
xine
critical
9.3
2007-01-16 CVE-2007-0254 Remote Format String vulnerability in Xine Errors.C
Format string vulnerability in the errors_create_window function in errors.c in xine-ui allows attackers to execute arbitrary code via unknown vectors.
network
low complexity
xine
critical
10.0