Debian Mplayer vulnerabilities
43 known vulnerabilities affecting debian/mplayer.
Total CVEs
43
CISA KEV
0
Public exploits
6
Exploited in wild
0
Severity breakdown
CRITICAL11HIGH3MEDIUM11LOW18
Vulnerabilities
Page 2 of 3
CVE-2004-1309P4CRITICALCVSS 10.0fixed in mplayer 1.0~pre6a-1 (bookworm)2004
CVE-2004-1309 [CRITICAL] CVE-2004-1309: mplayer - Heap-based buffer overflow in the demux_open_bmp function in demux_bmp.c for Uni...
Heap-based buffer overflow in the demux_open_bmp function in demux_bmp.c for Unix MPlayer 1.0pre5 allows remote attackers to execute arbitrary code via a bitmap (BMP) file containing a large biClrUsed field.
Scope: local
bookworm: resolved (fixed in 1.0~pre6a-1)
bullseye: resolved (fixed in 1.0~pre6a-1)
forky: resolved (fixed in 1.0~pre6a-1)
sid: resolved (fixed i
debian
CVE-2006-6172P4MEDIUMCVSS 7.5fixed in mplayer 1.0~rc1-11 (bookworm)2006
CVE-2006-6172 [HIGH] CVE-2006-6172: mplayer - Buffer overflow in the asmrp_eval function in the RealMedia RTSP stream handler ...
Buffer overflow in the asmrp_eval function in the RealMedia RTSP stream handler (asmrp.c) for Real Media input plugin, as used in (1) xine/xine-lib, (2) MPlayer 1.0rc1 and earlier, and possibly others, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a rulebook with a large number of rulematches.
Scope: local
bookworm: resol
debian
CVE-2008-4868P4LOWCVSS 10.0fixed in mplayer 1.0~rc2-14 (bookworm)2008
CVE-2008-4868 [CRITICAL] CVE-2008-4868: ffmpeg - Unspecified vulnerability in the avcodec_close function in libavcodec/utils.c in...
Unspecified vulnerability in the avcodec_close function in libavcodec/utils.c in FFmpeg 0.4.9 before r14787, as used by MPlayer, has unknown impact and attack vectors, related to a free "on random pointers."
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
debian
CVE-2008-5244P4LOWCVSS 10.0fixed in faad2 2.6.1-1 (bookworm)2008
CVE-2008-5244 [CRITICAL] CVE-2008-5244: faad2 - Unspecified vulnerability in xine-lib before 1.1.15 has unknown impact and attac...
Unspecified vulnerability in xine-lib before 1.1.15 has unknown impact and attack vectors related to libfaad. NOTE: due to the lack of details, it is not clear whether this is an issue in xine-lib or in libfaad.
Scope: local
bookworm: resolved (fixed in 2.6.1-1)
bullseye: resolved (fixed in 2.6.1-1)
forky: resolved (fixed in 2.6.1-1)
sid: resolved (fixed in 2.6.1-1)
debian
CVE-2008-0630P4MEDIUMCVSS 6.8fixed in mplayer 1.0~rc2-8 (bookworm)2008
CVE-2008-0630 [MEDIUM] CVE-2008-0630: mplayer - Buffer overflow in url.c in MPlayer 1.0rc2 and SVN before r25823 allows remote a...
Buffer overflow in url.c in MPlayer 1.0rc2 and SVN before r25823 allows remote attackers to execute arbitrary code via a crafted URL that prevents the IPv6 parsing code from setting a pointer to NULL, which causes the buffer to be reused by the unescape code.
Scope: local
bookworm: resolved (fixed in 1.0~rc2-8)
bullseye: resolved (fixed in 1.0~rc2-8)
forky: resolved
debian
CVE-2004-1311P4CRITICALCVSS 10.0fixed in mplayer 1.0~pre6a-1 (bookworm)2004
CVE-2004-1311 [CRITICAL] CVE-2004-1311: mplayer - Integer overflow in the real_setup_and_get_header function in real.c for Unix MP...
Integer overflow in the real_setup_and_get_header function in real.c for Unix MPlayer 1.0pre5 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a Real RTSP streaming media file with a -1 content-length field, which leads to a heap-based buffer overflow.
Scope: local
bookworm: resolved (fixed in 1.0~pre
debian
CVE-2007-1387P4LOWCVSS 7.6fixed in mplayer 1.0~rc1-13 (bookworm)2007
CVE-2007-1387 [HIGH] CVE-2007-1387: mplayer - The DirectShow loader (loader/dshow/DS_VideoDecoder.c) in MPlayer 1.0rc1 and ear...
The DirectShow loader (loader/dshow/DS_VideoDecoder.c) in MPlayer 1.0rc1 and earlier, as used in xine-lib, does not set the biSize before use in a memcpy, which allows user-assisted remote attackers to cause a buffer overflow and possibly execute arbitrary code, a different vulnerability than CVE-2007-1246.
Scope: local
bookworm: resolved (fixed in 1.0~rc1-13)
bullsey
debian
CVE-2008-0629P4MEDIUMCVSS 4.3fixed in mplayer 1.0~rc2-8 (bookworm)2008
CVE-2008-0629 [MEDIUM] CVE-2008-0629: mplayer - Buffer overflow in stream_cddb.c in MPlayer 1.0rc2 and SVN before r25824 allows ...
Buffer overflow in stream_cddb.c in MPlayer 1.0rc2 and SVN before r25824 allows remote user-assisted attackers to execute arbitrary code via a CDDB database entry containing a long album title.
Scope: local
bookworm: resolved (fixed in 1.0~rc2-8)
bullseye: resolved (fixed in 1.0~rc2-8)
forky: resolved (fixed in 1.0~rc2-8)
sid: resolved (fixed in 1.0~rc2-8)
trixie: r
debian
CVE-2022-38864P4MEDIUMCVSS 5.5fixed in mplayer 2:1.5+svn38408-1 (bookworm)2022
CVE-2022-38864 [MEDIUM] CVE-2022-38864: mplayer - Certain The MPlayer Project products are vulnerable to Buffer Overflow via the f...
Certain The MPlayer Project products are vulnerable to Buffer Overflow via the function mp_unescape03() of libmpdemux/mpeg_hdr.c. This affects mencoder SVN-r38374-13.0.1 and mplayer SVN-r38374-13.0.1.
Scope: local
bookworm: resolved (fixed in 2:1.5+svn38408-1)
bullseye: resolved (fixed in 2:1.4+ds1-1+deb11u1)
forky: resolved (fixed in 2:1.5+svn38408-1)
sid: resolv
debian
CVE-2022-38855P4LOWCVSS 5.5fixed in mplayer 2:1.5+svn38408-1 (bookworm)2022
CVE-2022-38855 [MEDIUM] CVE-2022-38855: mplayer - Certain The MPlayer Project products are vulnerable to Buffer Overflow via funct...
Certain The MPlayer Project products are vulnerable to Buffer Overflow via function gen_sh_video () of mplayer/libmpdemux/demux_mov.c. This affects mplayer SVN-r38374-13.0.1 and mencoder SVN-r38374-13.0.1.
Scope: local
bookworm: resolved (fixed in 2:1.5+svn38408-1)
bullseye: resolved (fixed in 2:1.4+ds1-1+deb11u1)
forky: resolved (fixed in 2:1.5+svn38408-1)
sid: r
debian
CVE-2022-38858P4LOWCVSS 5.5fixed in mplayer 2:1.5+svn38408-1 (bookworm)2022
CVE-2022-38858 [MEDIUM] CVE-2022-38858: mplayer - Certain The MPlayer Project products are vulnerable to Buffer Overflow via funct...
Certain The MPlayer Project products are vulnerable to Buffer Overflow via function mov_build_index() of libmpdemux/demux_mov.c. This affects mplayer SVN-r38374-13.0.1 and mencoder SVN-r38374-13.0.1.
Scope: local
bookworm: resolved (fixed in 2:1.5+svn38408-1)
bullseye: resolved (fixed in 2:1.4+ds1-1+deb11u1)
forky: resolved (fixed in 2:1.5+svn38408-1)
sid: resolve
debian
CVE-2022-38863P4LOWCVSS 5.5fixed in mplayer 2:1.5+svn38408-1 (bookworm)2022
CVE-2022-38863 [MEDIUM] CVE-2022-38863: mplayer - Certain The MPlayer Project products are vulnerable to Buffer Overflow via funct...
Certain The MPlayer Project products are vulnerable to Buffer Overflow via function mp_getbits() of libmpdemux/mpeg_hdr.c which affects mencoder and mplayer. This affects mecoder SVN-r38374-13.0.1 and mplayer SVN-r38374-13.0.1.
Scope: local
bookworm: resolved (fixed in 2:1.5+svn38408-1)
bullseye: resolved (fixed in 2:1.4+ds1-1+deb11u1)
forky: resolved (fixed in 2:
debian
CVE-2022-38861P4MEDIUMCVSS 5.5fixed in mplayer 2:1.5+svn38408-1 (bookworm)2022
CVE-2022-38861 [MEDIUM] CVE-2022-38861: mplayer - The MPlayer Project mplayer SVN-r38374-13.0.1 is vulnerable to memory corruption...
The MPlayer Project mplayer SVN-r38374-13.0.1 is vulnerable to memory corruption via function free_mp_image() of libmpcodecs/mp_image.c.
Scope: local
bookworm: resolved (fixed in 2:1.5+svn38408-1)
bullseye: resolved (fixed in 2:1.4+ds1-1+deb11u1)
forky: resolved (fixed in 2:1.5+svn38408-1)
sid: resolved (fixed in 2:1.5+svn38408-1)
trixie: resolved (fixed in 2:1.5+
debian
CVE-2022-38853P4LOWCVSS 5.5fixed in mplayer 2:1.5+svn38408-1 (bookworm)2022
CVE-2022-38853 [MEDIUM] CVE-2022-38853: mplayer - Certain The MPlayer Project products are vulnerable to Buffer Overflow via funct...
Certain The MPlayer Project products are vulnerable to Buffer Overflow via function asf_init_audio_stream() of libmpdemux/asfheader.c. This affects mplayer SVN-r38374-13.0.1 and mencoder SVN-r38374-13.0.1.
Scope: local
bookworm: resolved (fixed in 2:1.5+svn38408-1)
bullseye: open
forky: resolved (fixed in 2:1.5+svn38408-1)
sid: resolved (fixed in 2:1.5+svn38408-1)
debian
CVE-2022-38856P4LOWCVSS 5.5fixed in mplayer 2:1.5+svn38408-1 (bookworm)2022
CVE-2022-38856 [MEDIUM] CVE-2022-38856: mplayer - Certain The MPlayer Project products are vulnerable to Buffer Overflow via funct...
Certain The MPlayer Project products are vulnerable to Buffer Overflow via function mov_build_index() of libmpdemux/demux_mov.c. This affects mplayer SVN-r38374-13.0.1 and mencoder SVN-r38374-13.0.1.
Scope: local
bookworm: resolved (fixed in 2:1.5+svn38408-1)
bullseye: open
forky: resolved (fixed in 2:1.5+svn38408-1)
sid: resolved (fixed in 2:1.5+svn38408-1)
trixi
debian
CVE-2022-38860P4LOWCVSS 5.5fixed in mplayer 2:1.5+svn38408-1 (bookworm)2022
CVE-2022-38860 [MEDIUM] CVE-2022-38860: mplayer - Certain The MPlayer Project products are vulnerable to Divide By Zero via functi...
Certain The MPlayer Project products are vulnerable to Divide By Zero via function demux_open_avi() of libmpdemux/demux_avi.c which affects mencoder. This affects mplayer SVN-r38374-13.0.1 and mencoder SVN-r38374-13.0.1.
Scope: local
bookworm: resolved (fixed in 2:1.5+svn38408-1)
bullseye: resolved (fixed in 2:1.4+ds1-1+deb11u1)
forky: resolved (fixed in 2:1.5+svn
debian
CVE-2022-38851P4LOWCVSS 5.5fixed in mplayer 2:1.5+svn38408-1 (bookworm)2022
CVE-2022-38851 [MEDIUM] CVE-2022-38851: mplayer - Certain The MPlayer Project products are vulnerable to Out-of-bounds Read via fu...
Certain The MPlayer Project products are vulnerable to Out-of-bounds Read via function read_meta_record() of mplayer/libmpdemux/asfheader.c. This affects mplayer SVN-r38374-13.0.1 and mencoder SVN-r38374-13.0.1.
Scope: local
bookworm: resolved (fixed in 2:1.5+svn38408-1)
bullseye: resolved (fixed in 2:1.4+ds1-1+deb11u1)
forky: resolved (fixed in 2:1.5+svn38408-1)
debian
CVE-2022-38866P4LOWCVSS 5.5fixed in mplayer 2:1.5+svn38408-1 (bookworm)2022
CVE-2022-38866 [MEDIUM] CVE-2022-38866: mplayer - Certain The MPlayer Project products are vulnerable to Buffer Overflow via read_...
Certain The MPlayer Project products are vulnerable to Buffer Overflow via read_avi_header() of libmpdemux/aviheader.c . This affects mplayer SVN-r38374-13.0.1 and mencoder SVN-r38374-13.0.1.
Scope: local
bookworm: resolved (fixed in 2:1.5+svn38408-1)
bullseye: resolved (fixed in 2:1.4+ds1-1+deb11u1)
forky: resolved (fixed in 2:1.5+svn38408-1)
sid: resolved (fixed
debian
CVE-2022-38865P4LOWCVSS 5.5fixed in mplayer 2:1.5+svn38408-1 (bookworm)2022
CVE-2022-38865 [MEDIUM] CVE-2022-38865: mplayer - Certain The MPlayer Project products are vulnerable to Divide By Zero via the fu...
Certain The MPlayer Project products are vulnerable to Divide By Zero via the function demux_avi_read_packet of libmpdemux/demux_avi.c. This affects mplyer SVN-r38374-13.0.1 and mencoder SVN-r38374-13.0.1.
Scope: local
bookworm: resolved (fixed in 2:1.5+svn38408-1)
bullseye: resolved (fixed in 2:1.4+ds1-1+deb11u1)
forky: resolved (fixed in 2:1.5+svn38408-1)
sid: r
debian
CVE-2016-4352P4MEDIUMCVSS 5.5fixed in mplayer 2:1.3.0-2 (bookworm)2016
CVE-2016-4352 [MEDIUM] CVE-2016-4352: mplayer - Integer overflow in the demuxer function in libmpdemux/demux_gif.c in Mplayer al...
Integer overflow in the demuxer function in libmpdemux/demux_gif.c in Mplayer allows remote attackers to cause a denial of service (crash) via large dimensions in a gif file.
Scope: local
bookworm: resolved (fixed in 2:1.3.0-2)
bullseye: resolved (fixed in 2:1.3.0-2)
forky: resolved (fixed in 2:1.3.0-2)
sid: resolved (fixed in 2:1.3.0-2)
trixie: resolved (fixed in 2
debian