Vulnerabilities > Xiph > Critical

DATE CVE VULNERABILITY TITLE RISK
2008-04-08 CVE-2008-1686 Numeric Errors vulnerability in multiple products
Array index vulnerability in Speex 1.1.12 and earlier, as used in libfishsound 0.9.0 and earlier, including Illiminable DirectShow Filters and Annodex Plugins for Firefox, xine-lib before 1.1.12, and many other products, allows remote attackers to execute arbitrary code via a header structure containing a negative offset, which is used to dereference a function pointer.
network
xine xiph CWE-189
critical
9.3
2007-03-08 CVE-2007-1344 Unspecified vulnerability in Xiph Icecast Ezstream
Multiple buffer overflows in src/ezstream.c in Ezstream before 0.3.0 allow remote attackers to execute arbitrary code via a crafted XML configuration file processed by the (1) urlParse function, which causes a stack-based overflow and the (2) ReplaceString function, which causes a heap-based overflow.
network
xiph
critical
9.3