cbcvebase.

Debian Mplayer vulnerabilities

43 known vulnerabilities affecting debian/mplayer.

Total CVEs
43
CISA KEV
0
Public exploits
6
Exploited in wild
0
Severity breakdown
CRITICAL11HIGH3MEDIUM11LOW18

Vulnerabilities

Page 1 of 3
CVE-2008-1558P3MEDIUMCVSS 10.0PoCfixed in mplayer 1.0~rc2-10 (bookworm)2008
CVE-2008-1558 [CRITICAL] CVE-2008-1558: mplayer - Uncontrolled array index in the sdpplin_parse function in stream/realrtsp/sdppli... Uncontrolled array index in the sdpplin_parse function in stream/realrtsp/sdpplin.c in MPlayer 1.0 rc2 allows remote attackers to overwrite memory and execute arbitrary code via a large streamid SDP parameter. NOTE: this issue has been referred to as an integer overflow. Scope: local bookworm: resolved (fixed in 1.0~rc2-10) bullseye: resolved (fixed in 1.0~rc2-10)
debian
CVE-2004-0386P3CRITICALCVSS 10.0PoCfixed in mplayer 1.0~pre6a-1 (bookworm)2004
CVE-2004-0386 [CRITICAL] CVE-2004-0386: mplayer - Buffer overflow in the HTTP parser for MPlayer 1.0pre3 and earlier, 0.90, and 0.... Buffer overflow in the HTTP parser for MPlayer 1.0pre3 and earlier, 0.90, and 0.91 allows remote attackers to execute arbitrary code via a long Location header. Scope: local bookworm: resolved (fixed in 1.0~pre6a-1) bullseye: resolved (fixed in 1.0~pre6a-1) forky: resolved (fixed in 1.0~pre6a-1) sid: resolved (fixed in 1.0~pre6a-1) trixie: resolved (fixed in 1.0~p
debian
CVE-2011-3625P3CRITICALCVSS 9.3PoCfixed in mplayer 2:1.0~rc4.dfsg1+svn33713-2 (bookworm)2011
CVE-2011-3625 [CRITICAL] CVE-2011-3625: mplayer - Stack-based buffer overflow in the sub_read_line_sami function in subreader.c in... Stack-based buffer overflow in the sub_read_line_sami function in subreader.c in MPlayer, as used in SMPlayer 0.6.9, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in a SAMI subtitle file. Scope: local bookworm: resolved (fixed in 2:1.0~rc4.dfsg1+svn33713-2) bullseye: resolved (fixed in 2:1.0~rc4.
debian
CVE-2008-0485P3CRITICALCVSS 9.3PoCfixed in mplayer 1.0~rc2-8 (bookworm)2008
CVE-2008-0485 [CRITICAL] CVE-2008-0485: mplayer - Array index error in libmpdemux/demux_mov.c in MPlayer 1.0 rc2 and earlier might... Array index error in libmpdemux/demux_mov.c in MPlayer 1.0 rc2 and earlier might allow remote attackers to execute arbitrary code via a QuickTime MOV file with a crafted stsc atom tag. Scope: local bookworm: resolved (fixed in 1.0~rc2-8) bullseye: resolved (fixed in 1.0~rc2-8) forky: resolved (fixed in 1.0~rc2-8) sid: resolved (fixed in 1.0~rc2-8) trixie: resolved
debian
CVE-2007-4938P3HIGHCVSS 7.6PoCfixed in mplayer 1.0~rc1-16.1 (bookworm)2007
CVE-2007-4938 [HIGH] CVE-2007-4938: mplayer - Heap-based buffer overflow in libmpdemux/aviheader.c in MPlayer 1.0rc1 and earli... Heap-based buffer overflow in libmpdemux/aviheader.c in MPlayer 1.0rc1 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a .avi file with certain large "indx truck size" and nEntriesInuse values, and a certain wLongsPerEntry value. Scope: local bookworm: resolved (fixed in 1.0~rc1-16.1) bullseye
debian
CVE-2013-6933P3LOWCVSS 7.5fixed in mplayer 2:1.1.1+svn37434-1 (bookworm)2013
CVE-2013-6933 [HIGH] CVE-2013-6933: mplayer - The parseRTSPRequestString function in Live Networks Live555 Streaming Media 201... The parseRTSPRequestString function in Live Networks Live555 Streaming Media 2011.08.13 through 2013.11.25, as used in VideoLAN VLC Media Player, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a (1) space or (2) tab character at the beginning of an RTSP message, which triggers an integer underflow, infinite loop, a
debian
CVE-2008-5616P3LOWCVSS 10.0fixed in mplayer 1.0~rc2-19 (bookworm)2008
CVE-2008-5616 [CRITICAL] CVE-2008-5616: mplayer - Stack-based buffer overflow in the demux_open_vqf function in libmpdemux/demux_v... Stack-based buffer overflow in the demux_open_vqf function in libmpdemux/demux_vqf.c in MPlayer 1.0 rc2 before r28150 allows remote attackers to execute arbitrary code via a malformed TwinVQ file. Scope: local bookworm: resolved (fixed in 1.0~rc2-19) bullseye: resolved (fixed in 1.0~rc2-19) forky: resolved (fixed in 1.0~rc2-19) sid: resolved (fixed in 1.0~rc2-19)
debian
CVE-2009-0385P3CRITICALCVSS 9.3fixed in ffmpeg 0.svn20080206-16 (bookworm)2009
CVE-2009-0385 [CRITICAL] CVE-2009-0385: ffmpeg - Integer signedness error in the fourxm_read_header function in libavformat/4xm.c... Integer signedness error in the fourxm_read_header function in libavformat/4xm.c in FFmpeg before revision 16846 allows remote attackers to execute arbitrary code via a malformed 4X movie file with a large current_track value, which triggers a NULL pointer dereference. Scope: local bookworm: resolved (fixed in 0.svn20080206-16) bullseye: resolved (fixed in 0.svn200
debian
CVE-2007-2948P3CRITICALCVSS 9.3fixed in mplayer 1.0~rc1-14 (bookworm)2007
CVE-2007-2948 [CRITICAL] CVE-2007-2948: mplayer - Multiple stack-based buffer overflows in stream/stream_cddb.c in MPlayer before ... Multiple stack-based buffer overflows in stream/stream_cddb.c in MPlayer before 1.0rc1try3 allow remote attackers to execute arbitrary code via a CDDB entry with a long (1) album title or (2) category. Scope: local bookworm: resolved (fixed in 1.0~rc1-14) bullseye: resolved (fixed in 1.0~rc1-14) forky: resolved (fixed in 1.0~rc1-14) sid: resolved (fixed in 1.0~rc1
debian
CVE-2010-2062P3MEDIUMCVSS 7.5fixed in mplayer 2:1.0~rc3+svn20100502-3 (bookworm)2010
CVE-2010-2062 [HIGH] CVE-2010-2062: mplayer - Integer underflow in the real_get_rdt_chunk function in real.c, as used in modul... Integer underflow in the real_get_rdt_chunk function in real.c, as used in modules/access/rtsp/real.c in VideoLAN VLC media player before 1.0.1 and stream/realrtsp/real.c in MPlayer before r29447, allows remote attackers to execute arbitrary code via a crafted length value in an RDT chunk header. Scope: local bookworm: resolved (fixed in 2:1.0~rc3+svn20100502-3) bulls
debian
CVE-2004-1310P3CRITICALCVSS 10.0fixed in mplayer 1.0~pre6a-1 (bookworm)2004
CVE-2004-1310 [CRITICAL] CVE-2004-1310: mplayer - Stack-based buffer overflow in the asf_mmst_streaming.c functionality for MPlaye... Stack-based buffer overflow in the asf_mmst_streaming.c functionality for MPlayer 1.0pre5 allows remote attackers to execute arbitrary code via a large MMST stream packet. Scope: local bookworm: resolved (fixed in 1.0~pre6a-1) bullseye: resolved (fixed in 1.0~pre6a-1) forky: resolved (fixed in 1.0~pre6a-1) sid: resolved (fixed in 1.0~pre6a-1) trixie: resolved (fix
debian
CVE-2008-3827P3MEDIUMCVSS 9.3fixed in mplayer 1.0~rc2-18 (bookworm)2008
CVE-2008-3827 [CRITICAL] CVE-2008-3827: mplayer - Multiple integer underflows in the Real demuxer (demux_real.c) in MPlayer 1.0_rc... Multiple integer underflows in the Real demuxer (demux_real.c) in MPlayer 1.0_rc2 and earlier allow remote attackers to cause a denial of service (process termination) and possibly execute arbitrary code via a crafted video file that causes the stream_read function to read or write arbitrary memory. Scope: local bookworm: resolved (fixed in 1.0~rc2-18) bullseye: r
debian
CVE-2008-4610P4LOWCVSS 4.3PoCfixed in ffmpeg 7:2.4.1-1 (bookworm)2008
CVE-2008-4610 [MEDIUM] CVE-2008-4610: ffmpeg - MPlayer allows remote attackers to cause a denial of service (application crash)... MPlayer allows remote attackers to cause a denial of service (application crash) via (1) a malformed AAC file, as demonstrated by lol-vlc.aac; or (2) a malformed Ogg Media (OGM) file, as demonstrated by lol-ffplay.ogm, different vectors than CVE-2007-6718. Scope: local bookworm: resolved (fixed in 7:2.4.1-1) bullseye: resolved (fixed in 7:2.4.1-1) forky: resolved (fi
debian
CVE-2005-4048P3MEDIUMCVSS 7.5fixed in ffmpeg 0.cvs20050918-5.1 (bookworm)2005
CVE-2005-4048 [HIGH] CVE-2005-4048: ffmpeg - Heap-based buffer overflow in the avcodec_default_get_buffer function (utils.c) ... Heap-based buffer overflow in the avcodec_default_get_buffer function (utils.c) in FFmpeg libavcodec 0.4.9-pre1 and earlier, as used in products such as (1) mplayer, (2) xine-lib, (3) Xmovie, and (4) GStreamer, allows remote attackers to execute arbitrary commands via small PNG images with palettes. Scope: local bookworm: resolved (fixed in 0.cvs20050918-5.1) bullseye:
debian
CVE-2008-4866P3CRITICALCVSS 10.0fixed in ffmpeg 0.svn20080206-14 (bookworm)2008
CVE-2008-4866 [CRITICAL] CVE-2008-4866: ffmpeg - Multiple buffer overflows in libavformat/utils.c in FFmpeg 0.4.9 before r14715, ... Multiple buffer overflows in libavformat/utils.c in FFmpeg 0.4.9 before r14715, as used by MPlayer, allow context-dependent attackers to have an unknown impact via vectors related to execution of DTS generation code with a delay greater than MAX_REORDER_DELAY. Scope: local bookworm: resolved (fixed in 0.svn20080206-14) bullseye: resolved (fixed in 0.svn20080206-14)
debian
CVE-2008-0486P3HIGHCVSS 7.5fixed in mplayer 1.0~rc2-8 (bookworm)2008
CVE-2008-0486 [HIGH] CVE-2008-0486: mplayer - Array index vulnerability in libmpdemux/demux_audio.c in MPlayer 1.0rc2 and SVN ... Array index vulnerability in libmpdemux/demux_audio.c in MPlayer 1.0rc2 and SVN before r25917, and possibly earlier versions, as used in Xine-lib 1.1.10, might allow remote attackers to execute arbitrary code via a crafted FLAC tag, which triggers a buffer overflow. Scope: local bookworm: resolved (fixed in 1.0~rc2-8) bullseye: resolved (fixed in 1.0~rc2-8) forky: res
debian
CVE-2008-4867P3CRITICALCVSS 10.0fixed in ffmpeg 0.svn20080206-14 (bookworm)2008
CVE-2008-4867 [CRITICAL] CVE-2008-4867: ffmpeg - Buffer overflow in libavcodec/dca.c in FFmpeg 0.4.9 before r14917, as used by MP... Buffer overflow in libavcodec/dca.c in FFmpeg 0.4.9 before r14917, as used by MPlayer, allows context-dependent attackers to have an unknown impact via vectors related to an incorrect DCA_MAX_FRAME_SIZE value. Scope: local bookworm: resolved (fixed in 0.svn20080206-14) bullseye: resolved (fixed in 0.svn20080206-14) forky: resolved (fixed in 0.svn20080206-14) sid: r
debian
CVE-2004-0433P4CRITICALCVSS 10.0fixed in mplayer 1.0~pre6a-1 (bookworm)2004
CVE-2004-0433 [CRITICAL] CVE-2004-0433: mplayer - Multiple buffer overflows in the Real-Time Streaming Protocol (RTSP) client for ... Multiple buffer overflows in the Real-Time Streaming Protocol (RTSP) client for (1) MPlayer before 1.0pre4 and (2) xine lib (xine-lib) before 1-rc4, when playing Real RTSP (realrtsp) streams, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (a) long URLs, (b) long Real server responses, or (c) long Real Data Trans
debian
CVE-2007-1246P3MEDIUMCVSS 7.6fixed in mplayer 1.0~rc1-13 (bookworm)2007
CVE-2007-1246 [HIGH] CVE-2007-1246: mplayer - The DMO_VideoDecoder_Open function in loader/dmo/DMO_VideoDecoder.c in MPlayer 1... The DMO_VideoDecoder_Open function in loader/dmo/DMO_VideoDecoder.c in MPlayer 1.0rc1 and earlier, as used in xine-lib, does not set the biSize before use in a memcpy, which allows user-assisted remote attackers to cause a buffer overflow and possibly execute arbitrary code, a different vulnerability than CVE-2007-1387. Scope: local bookworm: resolved (fixed in 1.0~rc
debian
CVE-2006-4800P3HIGHCVSS 7.5fixed in ffmpeg 0.cvs20060329-1 (bookworm)2006
CVE-2006-4800 [HIGH] CVE-2006-4800: ffmpeg - Multiple buffer overflows in libavcodec in ffmpeg before 0.4.9_p20060530 allow r... Multiple buffer overflows in libavcodec in ffmpeg before 0.4.9_p20060530 allow remote attackers to cause a denial of service or possibly execute arbitrary code via multiple unspecified vectors in (1) dtsdec.c, (2) vorbis.c, (3) rm.c, (4) sierravmd.c, (5) smacker.c, (6) tta.c, (7) 4xm.c, (8) alac.c, (9) cook.c, (10) shorten.c, (11) smacker.c, (12) snow.c, and (13) tta.c
debian
Debian Mplayer vulnerabilities | cvebase