Vulnerabilities > Xine > Xine

DATE CVE VULNERABILITY TITLE RISK
2008-11-26 CVE-2008-5238 Numeric Errors vulnerability in Xine
Integer overflow in the real_parse_mdpr function in demux_real.c in xine-lib 1.1.12, and other versions before 1.1.15, allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted stream_name_size field.
network
xine CWE-189
7.1
2008-11-26 CVE-2008-5237 Numeric Errors vulnerability in Xine
Multiple integer overflows in xine-lib 1.1.12, and other 1.1.15 and earlier versions, allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via (1) crafted width and height values that are not validated by the mymng_process_header function in demux_mng.c before use in an allocation calculation or (2) crafted current_atom_size and string_size values processed by the parse_reference_atom function in demux_qt.c for an RDRF_ATOM string.
network
low complexity
xine CWE-189
critical
10.0
2008-11-26 CVE-2008-5236 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Xine
Multiple heap-based buffer overflows in xine-lib 1.1.12, and other 1.1.15 and earlier versions, allow remote attackers to execute arbitrary code via vectors related to (1) a crafted EBML element length processed by the parse_block_group function in demux_matroska.c; (2) a certain combination of sps, w, and h values processed by the real_parse_audio_specific_data and demux_real_send_chunk functions in demux_real.c; and (3) an unspecified combination of three values processed by the open_ra_file function in demux_realaudio.c.
network
xine CWE-119
critical
9.3
2008-11-26 CVE-2008-5235 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Xine
Heap-based buffer overflow in the demux_real_send_chunk function in src/demuxers/demux_real.c in xine-lib before 1.1.15 allows remote attackers to execute arbitrary code via a crafted Real Media file.
network
xine CWE-119
critical
9.3
2007-01-16 CVE-2007-0255 Remote Format String vulnerability in Xine 0.99.4
XINE 0.99.4 allows user-assisted remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a certain M3U file that contains a long #EXTINF line and contains format string specifiers in an invalid udp:// URI, possibly a variant of CVE-2007-0017.
network
xine
critical
9.3
2006-05-05 CVE-2006-2230 Remote Format String vulnerability in Xine 0.99.4
Multiple format string vulnerabilities in xiTK (xitk/main.c) in xine 0.99.4 might allow attackers to cause a denial of service via format string specifiers in an MP3 filename specified on the command line.
network
low complexity
xine
5.0
2006-04-20 CVE-2006-1905 Remote Format String vulnerability in Xine Playlist Handling
Multiple format string vulnerabilities in xiTK (xitk/main.c) in xine 0.99.3 allow remote attackers to execute arbitrary code via format string specifiers in a long filename on an EXTINFO line in a playlist file.
network
low complexity
xine
7.5
2005-01-10 CVE-2004-1188 The pnm_get_chunk function in xine 0.99.2 and earlier, and other packages such as MPlayer that use the same code, does not properly verify that the chunk size is less than the PREAMBLE_SIZE, which causes a read operation with a negative length that leads to a buffer overflow via (1) RMF_TAG, (2) DATA_TAG, (3) PROP_TAG, (4) MDPR_TAG, and (5) CONT_TAG values, a different vulnerability than CVE-2004-1187.
network
low complexity
mplayer xine mandrakesoft
critical
10.0
2005-01-10 CVE-2004-1187 Heap-based buffer overflow in the pnm_get_chunk function for xine 0.99.2, and other packages such as MPlayer that use the same code, allows remote attackers to execute arbitrary code via long PNA_TAG values, a different vulnerability than CVE-2004-1188.
network
low complexity
mplayer xine mandrakesoft
critical
10.0
2004-12-31 CVE-2004-1951 Remote File Overwrite vulnerability in Xine Xine, Xine-Lib and Xine-Ui
xine 1.x alpha, 1.x beta, and 1.0rc through 1.0rc3a, and xine-ui 0.9.21 to 0.9.23 allows remote attackers to overwrite arbitrary files via the (1) audio.sun_audio_device or (2) dxr3.devicename options in an MRL link.
network
low complexity
xine
5.0