Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
xine xine-lib 1.1.15 vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2009-1274
Integer overflow in the qt_error parse_trak_atom function in demuxers/demux_qt.c in xine-lib 1.1.16.2 and previous versions allows remote malicious users to execute arbitrary code via a Quicktime movie file with a large count value in an STTS atom, which triggers a heap-based buf...
Xine Xine-lib 1.1.11
Xine Xine-lib 1.1.11.1
Xine Xine-lib 1.1.10
Xine Xine-lib 1.1.14
Xine Xine-lib 1.1.13
Xine Xine-lib 1.1.16.1
Xine Xine-lib 1.1.16.2
Xine Xine-lib 1.1.15
Xine Xine-lib 1.1.12
Xine Xine-lib 1.1.1
Xine Xine-lib 1.1.10.1
Xine Xine-lib 1.1.0
NA
CVE-2008-5233
xine-lib 1.1.12, and other versions prior to 1.1.15, does not check for failure of malloc in circumstances including (1) the mymng_process_header function in demux_mng.c, (2) the open_mod_file function in demux_mod.c, and (3) frame_buffer allocation in the real_parse_audio_specif...
Xine Xine-lib 1.1.10.1
Xine Xine-lib 1.1.10
Xine Xine-lib 1.1.4
Xine Xine-lib 1.1.3
Xine Xine-lib 1.0
Xine Xine-lib 1
Xine Xine-lib 1.1.11.1
Xine Xine-lib 1.1.11
Xine Xine-lib 1.1.6
Xine Xine-lib 1.1.5
Xine Xine-lib 1.0.2
Xine Xine-lib 1.0.1
Xine Xine-lib 1 Beta11
Xine Xine-lib 1 Beta10
Xine Xine-lib 1 Beta3
Xine Xine-lib 1 Beta2
Xine Xine-lib 1.1.13
Xine Xine-lib
Xine Xine-lib 1.1.12
Xine Xine-lib 1.1.8
Xine Xine-lib 1.1.7
Xine Xine-lib 1.0.3a
NA
CVE-2008-5234
Multiple heap-based buffer overflows in xine-lib 1.1.12, and other versions prior to 1.1.15, allow remote malicious users to execute arbitrary code via vectors related to (1) a crafted metadata atom size processed by the parse_moov_atom function in demux_qt.c and (2) frame readin...
Xine Xine-lib 1.1.11.1
Xine Xine-lib 1.1.11
Xine Xine-lib 1.1.10.1
Xine Xine-lib 1.1.5
Xine Xine-lib 1.1.4
Xine Xine-lib 1.0.1
Xine Xine-lib 1.0
Xine Xine-lib 1
Xine Xine-lib 1 Beta10
Xine Xine-lib 1 Beta9
Xine Xine-lib 1 Beta2
Xine Xine-lib 1 Beta1
Xine Xine-lib
Xine Xine-lib 1.1.12
Xine Xine-lib 1.1.7
Xine Xine-lib 1.1.6
Xine Xine-lib 1.1.0
Xine Xine-lib 1.0.2
Xine Xine-lib 1 Beta12
Xine Xine-lib 1 Beta11
Xine Xine-lib 1 Beta4
Xine Xine-lib 1 Beta3
NA
CVE-2008-5237
Multiple integer overflows in xine-lib 1.1.12, and other 1.1.15 and previous versions versions, allow remote malicious users to cause a denial of service (crash) or possibly execute arbitrary code via (1) crafted width and height values that are not validated by the mymng_process...
Xine Xine 1.0.3a
Xine Xine 1.0.2
Xine Xine 1
Xine Xine 1.1.4
Xine Xine
Xine Xine 1.1.3
Xine Xine 1.1.2
Xine Xine 0.9.13
Xine Xine 1.1.11
Xine Xine 1.0.1
Xine Xine 1.0
Xine Xine 1.1.1
Xine Xine 1.1.0
Xine Xine 1.1.11.1
Xine Xine 1.1.10.1
NA
CVE-2008-5238
Integer overflow in the real_parse_mdpr function in demux_real.c in xine-lib 1.1.12, and other versions prior to 1.1.15, allows remote malicious users to cause a denial of service (crash) or possibly execute arbitrary code via a crafted stream_name_size field.
Xine Xine 1.0.1
Xine Xine 1.0
Xine Xine 1
Xine Xine 1.1.1
Xine Xine 1.1.0
Xine Xine 1.1.11.1
Xine Xine 1.1.10.1
Xine Xine 1.1.3
Xine Xine 1.1.2
Xine Xine 0.9.13
Xine Xine 1.1.11
Xine Xine 1.0.3a
Xine Xine 1.0.2
Xine Xine
Xine Xine 1.1.4
NA
CVE-2008-5242
demux_qt.c in xine-lib 1.1.12, and other 1.1.15 and previous versions versions, does not validate the count field before calling calloc for STSD_ATOM atom allocation, which allows remote malicious users to cause a denial of service (crash) or possibly execute arbitrary code via a...
Xine Xine-lib 1.1.10.1
Xine Xine-lib 1.1.10
Xine Xine-lib 1.1.4
Xine Xine-lib 1.1.3
Xine Xine-lib 1.0
Xine Xine-lib 1
Xine Xine-lib 1 Beta9
Xine Xine-lib 1 Beta8
Xine Xine-lib 1 Beta1
Xine Xine-lib 0.9.13
Xine Xine-lib 1.1.14
Xine Xine-lib 1.1.11.1
Xine Xine-lib 1.1.11
Xine Xine-lib 1.1.6
Xine Xine-lib 1.1.5
Xine Xine-lib 1.0.2
Xine Xine-lib 1.0.1
Xine Xine-lib 1 Beta11
Xine Xine-lib 1 Beta10
Xine Xine-lib 1 Beta3
Xine Xine-lib 1 Beta2
Xine Xine-lib 1.1.9
NA
CVE-2008-5243
The real_parse_headers function in demux_real.c in xine-lib 1.1.12, and other 1.1.15 and previous versions versions, relies on an untrusted input length value to "reindex into an allocated buffer," which allows remote malicious users to cause a denial of service (crash)...
Xine Xine-lib 1.1.10.1
Xine Xine-lib 1.1.10
Xine Xine-lib 1.1.4
Xine Xine-lib 1.1.3
Xine Xine-lib 1
Xine Xine-lib 1 Beta9
Xine Xine-lib 1 Beta8
Xine Xine-lib 0.9.13
Xine Xine-lib 1.1.14
Xine Xine-lib 1.1.11.1
Xine Xine-lib 1.1.11
Xine Xine-lib 1.1.6
Xine Xine-lib 1.1.5
Xine Xine-lib 1.0.2
Xine Xine-lib 1.0.1
Xine Xine-lib 1.0
Xine Xine-lib 1 Beta11
Xine Xine-lib 1 Beta10
Xine Xine-lib 1 Beta3
Xine Xine-lib 1 Beta2
Xine Xine-lib 1 Beta1
Xine Xine-lib 1.1.9
NA
CVE-2008-5246
Multiple heap-based buffer overflows in xine-lib prior to 1.1.15 allow remote malicious users to execute arbitrary code via vectors that send ID3 data to the (1) id3v22_interp_frame and (2) id3v24_interp_frame functions in src/demuxers/id3.c. NOTE: the provenance of this informat...
Xine Xine-lib 1.1.10
Xine Xine-lib 1.1.9
Xine Xine-lib 1.1.3
Xine Xine-lib 1.1.2
Xine Xine-lib 1
Xine Xine-lib 1 Beta8
Xine Xine-lib 1 Beta7
Xine Xine-lib 0.9.13
Xine Xine-lib
Xine Xine-lib 1.1.13
Xine Xine-lib 1.1.12
Xine Xine-lib 1.1.11.1
Xine Xine-lib 1.1.7
Xine Xine-lib 1.1.6
Xine Xine-lib 1.1.0
Xine Xine-lib 1.0.2
Xine Xine-lib 1 Beta12
Xine Xine-lib 1 Beta11
Xine Xine-lib 1 Beta4
Xine Xine-lib 1 Beta3
Xine Xine-lib 1.1.9.1
Xine Xine-lib 1.1.8
NA
CVE-2008-5248
xine-lib prior to 1.1.15 allows remote malicious users to cause a denial of service (crash) via "MP3 files with metadata consisting only of separators."
Xine Xine-lib 1.1.10.1
Xine Xine-lib 1.1.10
Xine Xine-lib 1.1.3
Xine Xine-lib 1.1.13
Xine Xine-lib 1.1.12
Xine Xine-lib 1.1.8
Xine Xine-lib 1.1.7
Xine Xine-lib 1.1.6
Xine Xine-lib 1.1.0
Xine Xine-lib 1.0.2
Xine Xine-lib 1
Xine Xine-lib 1 Beta12
Xine Xine-lib 1 Beta11
Xine Xine-lib 1 Beta4
Xine Xine-lib 1 Beta3
Xine Xine-lib 1.1.2
Xine Xine-lib 1 Beta8
Xine Xine-lib 1 Beta7
Xine Xine-lib 0.9.13
Xine Xine-lib 1.1.14
Xine Xine-lib 1.1.9
Xine Xine-lib 1.1.9.1
NA
CVE-2008-5235
Heap-based buffer overflow in the demux_real_send_chunk function in src/demuxers/demux_real.c in xine-lib prior to 1.1.15 allows remote malicious users to execute arbitrary code via a crafted Real Media file. NOTE: some of these details are obtained from third party information.
Xine Xine 1.1.2
Xine Xine 1.1.1
Xine Xine 1.1.0
Xine Xine 1
Xine Xine 1.1.3
Xine Xine 0.9.13
Xine Xine 1.1.11
Xine Xine 1.0.3a
Xine Xine 1.0.2
Xine Xine
Xine Xine 1.1.11.1
Xine Xine 1.1.10.1
Xine Xine 1.0.1
Xine Xine 1.0
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-33572
CVE-2024-24919
CVE-2024-0230
CVE-2024-32714
HTML injection
local file inclusion
CVE-2024-31098
CVE-2024-31244
privilege
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »