cbcvebase.

Xine Xine-Lib vulnerabilities

38 known vulnerabilities affecting xine/xine-lib.

Total CVEs
38
CISA KEV
0
Public exploits
11
Exploited in wild
0
Severity breakdown
CRITICAL9HIGH9MEDIUM20

Vulnerabilities

Page 2 of 2
CVE-2005-1195P4HIGHCVSS 7.5v1_beta1v1_beta2+13 more2005-05-02
CVE-2005-1195 [HIGH] CVE-2005-1195: Multiple heap-based buffer overflows in the code used to handle (1) MMS over TCP (MMST) streams or ( Multiple heap-based buffer overflows in the code used to handle (1) MMS over TCP (MMST) streams or (2) RealMedia RTSP streams in xine-lib before 1.0, and other products that use xine-lib such as MPlayer 1.0pre6 and earlier, allow remote malicious servers to execute arbitrary code.
nvd
CVE-2008-5244P4CRITICALCVSS 10.0≤ 1.1.15v0.9.13+35 more2008-11-26
CVE-2008-5244 [CRITICAL] CVE-2008-5244: Unspecified vulnerability in xine-lib before 1.1.15 has unknown impact and attack vectors related to Unspecified vulnerability in xine-lib before 1.1.15 has unknown impact and attack vectors related to libfaad. NOTE: due to the lack of details, it is not clear whether this is an issue in xine-lib or in libfaad.
nvd
CVE-2009-0698P4HIGHCVSS 7.5v1.1.16.12009-02-23
CVE-2009-0698 [HIGH] CVE-2009-0698: Integer overflow in the 4xm demuxer (demuxers/demux_4xm.c) in xine-lib 1.1.16.1 allows remote attack Integer overflow in the 4xm demuxer (demuxers/demux_4xm.c) in xine-lib 1.1.16.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a 4X movie file with a large current_track value, a similar issue to CVE-2009-0385.
nvd
CVE-2006-4799P4HIGHCVSS 7.5≤ 1.1.1v1.0.1+2 more2006-09-14
CVE-2006-4799 [HIGH] CVE-2006-4799: Buffer overflow in ffmpeg for xine-lib before 1.1.2 might allow context-dependent attackers to execu Buffer overflow in ffmpeg for xine-lib before 1.1.2 might allow context-dependent attackers to execute arbitrary code via a crafted AVI file and "bad indexes", a different vulnerability than CVE-2005-4048 and CVE-2006-2802.
nvd
CVE-2008-5245P4CRITICALCVSS 9.3≤ 1.1.14v0.9.13+34 more2008-11-26
CVE-2008-5245 [CRITICAL] CWE-119 CVE-2008-5245: xine-lib before 1.1.15 performs V4L video frame preallocation before ascertaining the required lengt xine-lib before 1.1.15 performs V4L video frame preallocation before ascertaining the required length, which has unknown impact and attack vectors, possibly related to a buffer overflow in the open_video_capture_device function in src/input/input_v4l.c.
nvd
CVE-2004-1188P4CRITICALCVSS 10.0v0.9.8v0.9.13+26 more2005-01-10
CVE-2004-1188 [CRITICAL] CVE-2004-1188: The pnm_get_chunk function in xine 0.99.2 and earlier, and other packages such as MPlayer that use t The pnm_get_chunk function in xine 0.99.2 and earlier, and other packages such as MPlayer that use the same code, does not properly verify that the chunk size is less than the PREAMBLE_SIZE, which causes a read operation with a negative length that leads to a buffer overflow via (1) RMF_TAG, (2) DATA_TAG, (3) PROP_TAG, (4) MDPR_TAG, and (5) CONT_TAG values,
nvd
CVE-2008-5242P4MEDIUMCVSS 6.8≤ 1.1.15v0.9.13+35 more2008-11-26
CVE-2008-5242 [MEDIUM] CWE-119 CVE-2008-5242: demux_qt.c in xine-lib 1.1.12, and other 1.1.15 and earlier versions, does not validate the count fi demux_qt.c in xine-lib 1.1.12, and other 1.1.15 and earlier versions, does not validate the count field before calling calloc for STSD_ATOM atom allocation, which allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted media file.
nvd
CVE-2006-2200P4MEDIUMCVSS 5.1v1.1.02006-06-28
CVE-2006-2200 [MEDIUM] CWE-119 CVE-2006-2200: Stack-based buffer overflow in libmms, as used by (a) MiMMS 0.0.9 and (b) xine-lib 1.1.0 and earlier Stack-based buffer overflow in libmms, as used by (a) MiMMS 0.0.9 and (b) xine-lib 1.1.0 and earlier, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via the (1) send_command, (2) string_utf16, (3) get_data, and (4) get_media_packet functions, and possibly other functions.
nvd
CVE-2004-1455P4MEDIUMCVSS 5.1v1_beta1v1_beta2+16 more2004-12-31
CVE-2004-1455 [MEDIUM] CVE-2004-1455: Stack-based buffer overflow in Xine-lib-rc5 in xine-lib 1_rc5-r2 and earlier allows remote attackers Stack-based buffer overflow in Xine-lib-rc5 in xine-lib 1_rc5-r2 and earlier allows remote attackers to execute arbitrary code via crafted playlists that result in a long vcd:// URL.
nvd
CVE-2008-5239P4MEDIUMCVSS 4.3v0.9.13v1+33 more2008-11-26
CVE-2008-5239 [MEDIUM] CWE-119 CVE-2008-5239: xine-lib 1.1.12, and other 1.1.15 and earlier versions, does not properly handle (a) negative and (b xine-lib 1.1.12, and other 1.1.15 and earlier versions, does not properly handle (a) negative and (b) zero values during unspecified read function calls in input_file.c, input_net.c, input_smb.c, and input_http.c, which allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via vectors such as (1) a file or (2)
nvd
CVE-2008-5240P4MEDIUMCVSS 4.3≤ 1.1.15v0.9.13+35 more2008-11-26
CVE-2008-5240 [MEDIUM] CWE-119 CVE-2008-5240: xine-lib 1.1.12, and other 1.1.15 and earlier versions, relies on an untrusted input value to determ xine-lib 1.1.12, and other 1.1.15 and earlier versions, relies on an untrusted input value to determine the memory allocation and does not check the result for (1) the MATROSKA_ID_TR_CODECPRIVATE track entry element processed by demux_matroska.c; and (2) PROP_TAG, (3) MDPR_TAG, and (4) CONT_TAG chunks processed by the real_parse_headers function in de
nvd
CVE-2008-5233P4MEDIUMCVSS 4.3≤ 1.1.14v0.9.13+34 more2008-11-26
CVE-2008-5233 [MEDIUM] CWE-119 CVE-2008-5233: xine-lib 1.1.12, and other versions before 1.1.15, does not check for failure of malloc in circumsta xine-lib 1.1.12, and other versions before 1.1.15, does not check for failure of malloc in circumstances including (1) the mymng_process_header function in demux_mng.c, (2) the open_mod_file function in demux_mod.c, and (3) frame_buffer allocation in the real_parse_audio_specific_data function in demux_real.c, which allows remote attackers to cause a
nvd
CVE-2004-1476P4MEDIUMCVSS 5.1v0.99v1_rc2+3 more2004-12-31
CVE-2004-1476 [MEDIUM] CVE-2004-1476: Stack-based buffer overflow in the VideoCD (VCD) code in xine-lib 1-rc2 through 1-rc5, as derived fr Stack-based buffer overflow in the VideoCD (VCD) code in xine-lib 1-rc2 through 1-rc5, as derived from libcdio, allows attackers to execute arbitrary code via a VideoCD with an unterminated disk label.
nvd
CVE-2008-5243P4MEDIUMCVSS 4.3≤ 1.1.15v0.9.13+35 more2008-11-26
CVE-2008-5243 [MEDIUM] CWE-20 CVE-2008-5243: The real_parse_headers function in demux_real.c in xine-lib 1.1.12, and other 1.1.15 and earlier ver The real_parse_headers function in demux_real.c in xine-lib 1.1.12, and other 1.1.15 and earlier versions, relies on an untrusted input length value to "reindex into an allocated buffer," which allows remote attackers to cause a denial of service (crash) via a crafted value, probably an array index error.
nvd
CVE-2008-5241P4MEDIUMCVSS 4.3≤ 1.1.15v0.9.13+35 more2008-11-26
CVE-2008-5241 [MEDIUM] CWE-189 CVE-2008-5241: Integer underflow in demux_qt.c in xine-lib 1.1.12, and other 1.1.15 and earlier versions, allows re Integer underflow in demux_qt.c in xine-lib 1.1.12, and other 1.1.15 and earlier versions, allows remote attackers to cause a denial of service (crash) via a crafted media file that results in a small value of moov_atom_size in a compressed MOV (aka CMOV_ATOM).
nvd
CVE-2008-5248P4MEDIUMCVSS 4.3≤ 1.1.15v0.9.13+35 more2008-11-26
CVE-2008-5248 [MEDIUM] CWE-20 CVE-2008-5248: xine-lib before 1.1.15 allows remote attackers to cause a denial of service (crash) via "MP3 files w xine-lib before 1.1.15 allows remote attackers to cause a denial of service (crash) via "MP3 files with metadata consisting only of separators."
nvd
CVE-2008-3231P4MEDIUMCVSS 4.3≤ 1.1.14v0.9.8+24 more2008-07-18
CVE-2008-3231 [MEDIUM] CWE-20 CVE-2008-3231: xine-lib before 1.1.15 allows remote attackers to cause a denial of service (crash) via a crafted OG xine-lib before 1.1.15 allows remote attackers to cause a denial of service (crash) via a crafted OGG file, as demonstrated by playing lol-ffplay.ogg with xine.
nvd
CVE-2008-5247P4MEDIUMCVSS 4.3≤ 1.1.15v0.9.13+35 more2008-11-26
CVE-2008-5247 [MEDIUM] CWE-189 CVE-2008-5247: The real_parse_audio_specific_data function in demux_real.c in xine-lib 1.1.12, and other 1.1.15 and The real_parse_audio_specific_data function in demux_real.c in xine-lib 1.1.12, and other 1.1.15 and earlier versions, uses an untrusted height (aka codec_data_length) value as a divisor, which allow remote attackers to cause a denial of service (divide-by-zero error and crash) via a zero value.
nvd
Xine Xine-Lib vulnerabilities | cvebase