Search CVE reports


Toggle filters

61 – 70 of 73 results


CVE-2008-0486

Medium priority

Some fixes available 6 of 7

Array index vulnerability in libmpdemux/demux_audio.c in MPlayer 1.0rc2 and SVN before r25917, and possibly earlier versions, as used in Xine-lib 1.1.10, might allow remote attackers to execute arbitrary code via a crafted FLAC...

2 affected packages

mplayer, xine-lib

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mplayer
xine-lib
Show less packages

CVE-2008-0485

Medium priority
Fixed

Array index error in libmpdemux/demux_mov.c in MPlayer 1.0 rc2 and earlier might allow remote attackers to execute arbitrary code via a QuickTime MOV file with a crafted stsc atom tag.

1 affected package

mplayer

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mplayer
Show less packages

CVE-2008-0238

Medium priority

Some fixes available 7 of 8

Multiple heap-based buffer overflows in the rmff_dump_cont function in input/libreal/rmff.c in xine-lib 1.1.9 allow remote attackers to execute arbitrary code via the SDP (1) Title, (2) Author, or (3) Copyright attribute, related...

2 affected packages

mplayer, xine-lib

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mplayer
xine-lib
Show less packages

CVE-2008-0225

Medium priority

Some fixes available 7 of 8

Heap-based buffer overflow in the rmff_dump_cont function in input/libreal/rmff.c in xine-lib 1.1.9 and earlier allows remote attackers to execute arbitrary code via the SDP Abstract attribute in an RTSP session, related to the...

2 affected packages

mplayer, xine-lib

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mplayer
xine-lib
Show less packages

CVE-2008-0073

Medium priority

Some fixes available 11 of 24

Array index error in the sdpplin_parse function in input/libreal/sdpplin.c in xine-lib 1.1.10.1 allows remote RTSP servers to execute arbitrary code via a large streamid SDP parameter.

3 affected packages

mplayer, vlc, xine-lib

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mplayer
vlc
xine-lib
Show less packages

CVE-2007-6718

Low priority
Ignored

MPlayer, possibly 1.0rc1, allows remote attackers to cause a denial of service (SIGSEGV and application crash) via (1) a malformed MP3 file, as demonstrated by lol-mplayer.mp3; (2) a malformed Ogg Vorbis file, as demonstrated by...

1 affected package

mplayer

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mplayer
Show less packages

CVE-2007-4938

Low priority
Fixed

Heap-based buffer overflow in libmpdemux/aviheader.c in MPlayer 1.0rc1 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a .avi file with certain large...

1 affected package

mplayer

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mplayer
Show less packages

CVE-2007-2948

Medium priority
Fixed

Multiple stack-based buffer overflows in stream/stream_cddb.c in MPlayer before 1.0rc1try3 allow remote attackers to execute arbitrary code via a CDDB entry with a long (1) album title or (2) category.

1 affected package

mplayer

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mplayer
Show less packages

CVE-2007-1246

Medium priority
Fixed

The DMO_VideoDecoder_Open function in loader/dmo/DMO_VideoDecoder.c in MPlayer 1.0rc1 and earlier, as used in xine-lib, does not set the biSize before use in a memcpy, which allows user-assisted remote attackers to cause a buffer...

2 affected packages

mplayer, xine-lib

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mplayer
xine-lib
Show less packages

CVE-2006-6172

Medium priority
Fixed

Buffer overflow in the asmrp_eval function in the RealMedia RTSP stream handler (asmrp.c) for Real Media input plugin, as used in (1) xine/xine-lib, (2) MPlayer 1.0rc1 and earlier, and possibly others, allows remote attackers to...

2 affected packages

mplayer, xine-lib

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mplayer
xine-lib
Show less packages