Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
xine-lib vulnerabilities and exploits
(subscribe to this query)
454
VMScore
CVE-2004-1476
Stack-based buffer overflow in the VideoCD (VCD) code in xine-lib 1-rc2 through 1-rc5, as derived from libcdio, allows malicious users to execute arbitrary code via a VideoCD with an unterminated disk label.
Xine Xine 0.9.18
Xine Xine 1 Rc2
Xine Xine-lib 0.99
Xine Xine-lib 1 Rc2
Xine Xine-lib 1 Rc3
Xine Xine 1 Rc5
Xine Xine-lib 1 Rc4
Xine Xine-lib 1 Rc5
Xine Xine 1 Rc3
Xine Xine 1 Rc4
Suse Suse Linux 8.2
Suse Suse Linux 9.0
Suse Suse Linux 9.2
Suse Suse Linux 8.0
Suse Suse Linux 8.1
Suse Suse Linux 9.1
445
VMScore
CVE-2009-1274
Integer overflow in the qt_error parse_trak_atom function in demuxers/demux_qt.c in xine-lib 1.1.16.2 and previous versions allows remote malicious users to execute arbitrary code via a Quicktime movie file with a large count value in an STTS atom, which triggers a heap-based buf...
Xine Xine-lib 1.1.11
Xine Xine-lib 1.1.11.1
Xine Xine-lib 1.1.10
Xine Xine-lib 1.1.14
Xine Xine-lib 1.1.13
Xine Xine-lib 1.1.16.1
Xine Xine-lib 1.1.16.2
Xine Xine-lib 1.1.15
Xine Xine-lib 1.1.12
Xine Xine-lib 1.1.1
Xine Xine-lib 1.1.10.1
Xine Xine-lib 1.1.0
383
VMScore
CVE-2008-5233
xine-lib 1.1.12, and other versions prior to 1.1.15, does not check for failure of malloc in circumstances including (1) the mymng_process_header function in demux_mng.c, (2) the open_mod_file function in demux_mod.c, and (3) frame_buffer allocation in the real_parse_audio_specif...
Xine Xine-lib 1.1.10.1
Xine Xine-lib 1.1.10
Xine Xine-lib 1.1.4
Xine Xine-lib 1.1.3
Xine Xine-lib 1.0
Xine Xine-lib 1
Xine Xine-lib 1.1.11.1
Xine Xine-lib 1.1.11
Xine Xine-lib 1.1.6
Xine Xine-lib 1.1.5
Xine Xine-lib 1.0.2
Xine Xine-lib 1.0.1
Xine Xine-lib 1 Beta11
Xine Xine-lib 1 Beta10
Xine Xine-lib 1 Beta3
Xine Xine-lib 1 Beta2
Xine Xine-lib 1.1.13
Xine Xine-lib
Xine Xine-lib 1.1.12
Xine Xine-lib 1.1.8
Xine Xine-lib 1.1.7
Xine Xine-lib 1.0.3a
383
VMScore
CVE-2008-5248
xine-lib prior to 1.1.15 allows remote malicious users to cause a denial of service (crash) via "MP3 files with metadata consisting only of separators."
Xine Xine-lib 1.1.10.1
Xine Xine-lib 1.1.10
Xine Xine-lib 1.1.3
Xine Xine-lib 1.1.13
Xine Xine-lib 1.1.12
Xine Xine-lib 1.1.8
Xine Xine-lib 1.1.7
Xine Xine-lib 1.1.6
Xine Xine-lib 1.1.0
Xine Xine-lib 1.0.2
Xine Xine-lib 1
Xine Xine-lib 1 Beta12
Xine Xine-lib 1 Beta11
Xine Xine-lib 1 Beta4
Xine Xine-lib 1 Beta3
Xine Xine-lib 1.1.2
Xine Xine-lib 1 Beta8
Xine Xine-lib 1 Beta7
Xine Xine-lib 0.9.13
Xine Xine-lib 1.1.14
Xine Xine-lib 1.1.9
Xine Xine-lib 1.1.9.1
383
VMScore
CVE-2008-5239
xine-lib 1.1.12, and other 1.1.15 and previous versions versions, does not properly handle (a) negative and (b) zero values during unspecified read function calls in input_file.c, input_net.c, input_smb.c, and input_http.c, which allows remote malicious users to cause a denial of...
Xine Xine-lib 1.1.13
Xine Xine-lib 1.1.9.1
Xine Xine-lib 1.1.8
Xine Xine-lib 1.1.7
Xine Xine-lib 1.0.3a
Xine Xine-lib 1.1.0
Xine Xine-lib 1
Xine Xine-lib 1 Beta12
Xine Xine-lib 1 Beta5
Xine Xine-lib 1 Beta4
Xine Xine-lib 1.1.11
Xine Xine-lib 1.1.10.1
Xine Xine-lib 1.1.4
Xine Xine-lib 1.1.3
Xine Xine-lib 1.0
Xine Xine-lib 1 Beta9
Xine Xine-lib 1 Beta8
Xine Xine-lib 1 Beta1
Xine Xine-lib 0.9.13
Xine Xine-lib 1.1.12
Xine Xine-lib 1.1.11.1
Xine Xine-lib 1.1.6
383
VMScore
CVE-2008-5240
xine-lib 1.1.12, and other 1.1.15 and previous versions versions, relies on an untrusted input value to determine the memory allocation and does not check the result for (1) the MATROSKA_ID_TR_CODECPRIVATE track entry element processed by demux_matroska.c; and (2) PROP_TAG, (3) M...
Xine Xine-lib 1.1.12
Xine Xine-lib 1.1.11.1
Xine Xine-lib 1.1.6
Xine Xine-lib 1.1.5
Xine Xine-lib 1.0.2
Xine Xine-lib 1.0.1
Xine Xine-lib 1
Xine Xine-lib 1.1.10
Xine Xine-lib 1.1.9
Xine Xine-lib 1.1.9.1
Xine Xine-lib 1.1.2
Xine Xine-lib 1.1.1
Xine Xine-lib 1.1.11
Xine Xine-lib 1.1.10.1
Xine Xine-lib 1.1.4
Xine Xine-lib 1.1.3
Xine Xine-lib 1.0
Xine Xine-lib 1 Beta9
Xine Xine-lib 1 Beta8
Xine Xine-lib 1 Beta1
Xine Xine-lib 0.9.13
Xine Xine-lib 1 Beta11
383
VMScore
CVE-2008-5241
Integer underflow in demux_qt.c in xine-lib 1.1.12, and other 1.1.15 and previous versions versions, allows remote malicious users to cause a denial of service (crash) via a crafted media file that results in a small value of moov_atom_size in a compressed MOV (aka CMOV_ATOM).
Xine Xine-lib 1.1.13
Xine Xine-lib 1.1.9.1
Xine Xine-lib 1.1.8
Xine Xine-lib 1.0.3a
Xine Xine-lib 1.1.0
Xine Xine-lib 1
Xine Xine-lib 1 Beta5
Xine Xine-lib 1 Beta4
Xine Xine-lib 1.1.11
Xine Xine-lib 1.1.10.1
Xine Xine-lib 1.1.4
Xine Xine-lib 1.1.3
Xine Xine-lib 1.0
Xine Xine-lib 1 Beta9
Xine Xine-lib 1 Beta8
Xine Xine-lib 1 Beta1
Xine Xine-lib 0.9.13
Xine Xine-lib 1.1.10
Xine Xine-lib 1.1.9
Xine Xine-lib 1.1.2
Xine Xine-lib 1.1.1
Xine Xine-lib 1 Beta7
383
VMScore
CVE-2008-5243
The real_parse_headers function in demux_real.c in xine-lib 1.1.12, and other 1.1.15 and previous versions versions, relies on an untrusted input length value to "reindex into an allocated buffer," which allows remote malicious users to cause a denial of service (crash)...
Xine Xine-lib 1.1.10.1
Xine Xine-lib 1.1.10
Xine Xine-lib 1.1.4
Xine Xine-lib 1.1.3
Xine Xine-lib 1
Xine Xine-lib 1 Beta9
Xine Xine-lib 1 Beta8
Xine Xine-lib 0.9.13
Xine Xine-lib 1.1.14
Xine Xine-lib 1.1.11.1
Xine Xine-lib 1.1.11
Xine Xine-lib 1.1.6
Xine Xine-lib 1.1.5
Xine Xine-lib 1.0.2
Xine Xine-lib 1.0.1
Xine Xine-lib 1.0
Xine Xine-lib 1 Beta11
Xine Xine-lib 1 Beta10
Xine Xine-lib 1 Beta3
Xine Xine-lib 1 Beta2
Xine Xine-lib 1 Beta1
Xine Xine-lib 1.1.9
383
VMScore
CVE-2008-5247
The real_parse_audio_specific_data function in demux_real.c in xine-lib 1.1.12, and other 1.1.15 and previous versions versions, uses an untrusted height (aka codec_data_length) value as a divisor, which allow remote malicious users to cause a denial of service (divide-by-zero er...
Xine Xine-lib 1.1.13
Xine Xine-lib 1.1.12
Xine Xine-lib 1.1.7
Xine Xine-lib 1.1.6
Xine Xine-lib 1.1.10.1
Xine Xine-lib 1.1.10
Xine Xine-lib 1.1.9
Xine Xine-lib 1.1.3
Xine Xine-lib 1.1.2
Xine Xine-lib 1
Xine Xine-lib 1 Beta8
Xine Xine-lib 1 Beta7
Xine Xine-lib 0.9.13
Xine Xine-lib 1.1.14
Xine Xine-lib 1.1.0
Xine Xine-lib 1.0.2
Xine Xine-lib 1 Beta12
Xine Xine-lib 1 Beta11
Xine Xine-lib 1 Beta4
Xine Xine-lib 1 Beta3
Xine Xine-lib 1.1.9.1
Xine Xine-lib 1.1.8
383
VMScore
CVE-2008-3231
xine-lib prior to 1.1.15 allows remote malicious users to cause a denial of service (crash) via a crafted OGG file, as demonstrated by playing lol-ffplay.ogg with xine.
Xine Xine-lib 1.1.1
Xine Xine-lib 1.1.0
Xine Xine-lib 1.1.13
Xine Xine-lib 1.1.2
Xine Xine-lib 1.1.4
Xine Xine-lib 1.1.5
Xine Xine-lib 1
Xine Xine-lib 1.0.2
Xine Xine-lib 1.0.1
Xine Xine-lib 1.1.10.1
Xine Xine-lib 1.1.11.1
Xine Xine-lib 1.1.8
Xine Xine-lib 1.1.9
Xine Xine-lib 0.99
Xine Xine-lib 1.0.3a
Xine Xine-lib 1.1.3
Xine Xine-lib 1.1.12
Xine Xine-lib 1.1.6
Xine Xine-lib 1.1.7
Xine Xine-lib 0.9.8
Xine Xine-lib 0.9.13
Xine Xine-lib 1.0
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
NULL pointer dereference
CVE-2023-52689
CVE-2024-23803
client side
CVE-2023-52696
information disclosure
CVE-2024-35843
CVE-2024-27130
CVE-2023-52697
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5