CVE-2006-1664
published 2006-04-07CVE-2006-1664: Buffer overflow in xine_list_delete_current in libxine 1.14 and earlier, as distributed in xine-lib 1.1.1 and earlier, allows remote attackers to execute…
PriorityP346high7.5CVSS 2.0
AVNACLAuNCPIPAP
EXPLOIT
EPSS
14.64%
96.2th percentile
Buffer overflow in xine_list_delete_current in libxine 1.14 and earlier, as distributed in xine-lib 1.1.1 and earlier, allows remote attackers to execute arbitrary code via a crafted MPEG stream.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | vlc | — | — |
| xine | xine-lib | <= 1.1.9 | — |
| xine | xine-lib | — | — |
| xine | xine-lib | — | — |
| xine | xine-lib | — | — |
| xine | xine-lib | — | — |
| xine | xine-lib | — | — |
| xine | xine-lib | — | — |
| xine | xine-lib | — | — |
| xine | xine-plugin | <= 1.1.9 | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_debian7.5LOW
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9wrh-g7c2-fv5f: Buffer overflow in xine_list_delete_current in libxine 1
ghsa_unreviewed·2022-05-01
CVE-2006-1664 [HIGH] GHSA-9wrh-g7c2-fv5f: Buffer overflow in xine_list_delete_current in libxine 1
Buffer overflow in xine_list_delete_current in libxine 1.14 and earlier, as distributed in xine-lib 1.1.1 and earlier, allows remote attackers to execute arbitrary code via a crafted MPEG stream.
GHSA
GHSA-fccg-vfm7-whwm: Buffer overflow in demuxers/demux_asf
ghsa_unreviewed·2022-05-01·CVSS 7.5
CVE-2008-1110 [HIGH] CWE-119 GHSA-fccg-vfm7-whwm: Buffer overflow in demuxers/demux_asf
Buffer overflow in demuxers/demux_asf.c (aka the ASF demuxer) in the xineplug_dmx_asf.so plugin in xine-lib before 1.1.10 allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a crafted ASF header. NOTE: this issue leads to a crash when an attack uses the CVE-2006-1664 exploit code, but it is different from CVE-2006-1664.
Debian
CVE-2006-1664: vlc - Buffer overflow in xine_list_delete_current in libxine 1.14 and earlier, as dist...
vendor_debian·2006·CVSS 7.5
CVE-2006-1664 [HIGH] CVE-2006-1664: vlc - Buffer overflow in xine_list_delete_current in libxine 1.14 and earlier, as dist...
Buffer overflow in xine_list_delete_current in libxine 1.14 and earlier, as distributed in xine-lib 1.1.1 and earlier, allows remote attackers to execute arbitrary code via a crafted MPEG stream.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No writeups or analysis indexed.
http://bugs.gentoo.org/show_bug.cgi?id=128838http://secunia.com/advisories/19853http://secunia.com/advisories/19856http://secunia.com/advisories/28666http://securitytracker.com/id?1015868http://sourceforge.net/project/shownotes.php?group_id=9655&release_id=571608http://www.gentoo.org/security/en/glsa/glsa-200604-16.xmlhttp://www.securityfocus.com/bid/17370http://www.securityfocus.com/data/vulnerabilities/exploits/xinelib_poc.plhttps://exchange.xforce.ibmcloud.com/vulnerabilities/25670https://www.exploit-db.com/exploits/1641https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00956.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-January/msg00976.htmlhttp://bugs.gentoo.org/show_bug.cgi?id=128838http://secunia.com/advisories/19853http://secunia.com/advisories/19856http://secunia.com/advisories/28666http://securitytracker.com/id?1015868http://sourceforge.net/project/shownotes.php?group_id=9655&release_id=571608http://www.gentoo.org/security/en/glsa/glsa-200604-16.xmlhttp://www.securityfocus.com/bid/17370http://www.securityfocus.com/data/vulnerabilities/exploits/xinelib_poc.plhttps://exchange.xforce.ibmcloud.com/vulnerabilities/25670https://www.exploit-db.com/exploits/1641https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00956.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-January/msg00976.html
2006-04-07
Published