CVE Tools

Xine

43 CVEs tracked since 2004. Since Mar 2004, none of them reached CISA KEV.

Xine CVEs per month

Mar 2004 to Nov 2008. Point at a month, or focus the strip and use the arrow keys.
Xine CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2004-0310
2004-04null or fewer
2004-0510
2004-06null or fewer
2004-07null or fewer
2004-08null or fewer
2004-09null or fewer
2004-10null or fewer
2004-1110
2004-1230
2005-0110
2005-0230
2005-03null or fewer
2005-04null or fewer
2005-0520
2005-06null or fewer
2005-07null or fewer
2005-08null or fewer
2005-09null or fewer
2005-1010
2005-11null or fewer
2005-12null or fewer
2006-01null or fewer
2006-02null or fewer
2006-03null or fewer
2006-0420
2006-05null or fewer
2006-0620
2006-07null or fewer
2006-08null or fewer
2006-09null or fewer
2006-10null or fewer
2006-11null or fewer
2006-12null or fewer
2007-0120
2007-02null or fewer
2007-03null or fewer
2007-04null or fewer
2007-05null or fewer
2007-06null or fewer
2007-07null or fewer
2007-08null or fewer
2007-09null or fewer
2007-10null or fewer
2007-11null or fewer
2007-12null or fewer
2008-0120
2008-0220
2008-0320
2008-0420
2008-05null or fewer
2008-06null or fewer
2008-07null or fewer
2008-08null or fewer
2008-09null or fewer
2008-10null or fewer
2008-11160

Products

The products that kept showing up in Xine's monthly top three, with their CVEs summed over those months.

  1. Xine-lib3313 months
  2. Xine138 months
  3. Gxine33 months
  4. Xine-plugin11 month
  5. Xine-ui11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Xine.

  1. CVE-2009-1274Integer overflow in the qt_error parse_trak_atom function in demuxers/demux_qt.c in xine-lib 1.1.16.2 and earlier allows remote attackers to execute arbitrary code via a Quicktime movie file with a...5.0
  2. CVE-2009-0698Integer overflow in the 4xm demuxer (demuxers/demux_4xm.c) in xine-lib 1.1.16.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a 4X movie file ...7.5
  3. CVE-2008-5241Integer underflow in demux_qt.c in xine-lib 1.1.12, and other 1.1.15 and earlier versions, allows remote attackers to cause a denial of service (crash) via a crafted media file that results in a sm...4.3
  4. CVE-2008-5242demux_qt.c in xine-lib 1.1.12, and other 1.1.15 and earlier versions, does not validate the count field before calling calloc for STSD_ATOM atom allocation, which allows remote attackers to cause a...6.8
  5. CVE-2008-5233xine-lib 1.1.12, and other versions before 1.1.15, does not check for failure of malloc in circumstances including (1) the mymng_process_header function in demux_mng.c, (2) the open_mod_file functi...4.3
  6. CVE-2008-5240xine-lib 1.1.12, and other 1.1.15 and earlier versions, relies on an untrusted input value to determine the memory allocation and does not check the result for (1) the MATROSKA_ID_TR_CODECPRIVATE t...4.3
  7. CVE-2008-5244Unspecified vulnerability in xine-lib before 1.1.15 has unknown impact and attack vectors related to libfaad. NOTE: due to the lack of details, it is not clear whether this is an issue in xine-lib...10.0
  8. CVE-2008-5238Integer overflow in the real_parse_mdpr function in demux_real.c in xine-lib 1.1.12, and other versions before 1.1.15, allows remote attackers to cause a denial of service (crash) or possibly execu...7.1
  9. CVE-2008-5248xine-lib before 1.1.15 allows remote attackers to cause a denial of service (crash) via "MP3 files with metadata consisting only of separators."4.3
  10. CVE-2008-5246Multiple heap-based buffer overflows in xine-lib before 1.1.15 allow remote attackers to execute arbitrary code via vectors that send ID3 data to the (1) id3v22_interp_frame and (2) id3v24_interp_f...9.3
  11. CVE-2008-5245xine-lib before 1.1.15 performs V4L video frame preallocation before ascertaining the required length, which has unknown impact and attack vectors, possibly related to a buffer overflow in the open...9.3
  12. CVE-2008-5236Multiple heap-based buffer overflows in xine-lib 1.1.12, and other 1.1.15 and earlier versions, allow remote attackers to execute arbitrary code via vectors related to (1) a crafted EBML element le...9.3
  13. CVE-2008-5243The real_parse_headers function in demux_real.c in xine-lib 1.1.12, and other 1.1.15 and earlier versions, relies on an untrusted input length value to "reindex into an allocated buffer," which all...4.3
  14. CVE-2008-5239xine-lib 1.1.12, and other 1.1.15 and earlier versions, does not properly handle (a) negative and (b) zero values during unspecified read function calls in input_file.c, input_net.c, input_smb.c, a...4.3
  15. CVE-2008-5234Multiple heap-based buffer overflows in xine-lib 1.1.12, and other versions before 1.1.15, allow remote attackers to execute arbitrary code via vectors related to (1) a crafted metadata atom size p...9.3

The record

Peak rank
#4 in Nov 2008
Busiest month shown
Nov 2008, 16 CVEs
Months with a KEV entry
0 since Mar 2004
Monthly snapshots
16 since 2004
Xine's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store