CyberSec.Space Logo
Back to CVE Browser

CVE-2008-5237

CRITICAL
10.0
CVSS Severity Score
EPSS Score0.0450%
EPSS Percentile11.69th
PublishedNov 26, 2008
Last ModifiedApr 23, 2026

Vulnerability Description

Multiple integer overflows in xine-lib 1.1.12, and other 1.1.15 and earlier versions, allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via (1) crafted width and height values that are not validated by the mymng_process_header function in demux_mng.c before use in an allocation calculation or (2) crafted current_atom_size and string_size values processed by the parse_reference_atom function in demux_qt.c for an RDRF_ATOM string.

Affected Platforms (CPE)

πŸ“¦
Xine

Xine

<= 1.1.5
πŸ“¦
Xine

Xine

= 0.9.13
πŸ“¦
Xine

Xine

= 1
πŸ“¦
Xine

Xine

= 1
πŸ“¦
Xine

Xine

= 1
πŸ“¦
Xine

Xine

= 1
πŸ“¦
Xine

Xine

= 1
πŸ“¦
Xine

Xine

= 1
πŸ“¦
Xine

Xine

= 1
πŸ“¦
Xine

Xine

= 1
πŸ“¦
Xine

Xine

= 1
πŸ“¦
Xine

Xine

= 1
πŸ“¦
Xine

Xine

= 1
πŸ“¦
Xine

Xine

= 1
πŸ“¦
Xine

Xine

= 1
πŸ“¦
Xine

Xine

= 1
πŸ“¦
Xine

Xine

= 1
πŸ“¦
Xine

Xine

= 1
πŸ“¦
Xine

Xine

= 1
πŸ“¦
Xine

Xine

= 1
πŸ“¦
Xine

Xine

= 1
πŸ“¦
Xine

Xine

= 1
πŸ“¦
Xine

Xine

= 1
πŸ“¦
Xine

Xine

= 1
πŸ“¦
Xine

Xine

= 1
πŸ“¦
Xine

Xine

= 1
πŸ“¦
Xine

Xine

= 1
πŸ“¦
Xine

Xine

= 1.0
πŸ“¦
Xine

Xine

= 1.0.1
πŸ“¦
Xine

Xine

= 1.0.2
πŸ“¦
Xine

Xine

= 1.0.3a
πŸ“¦
Xine

Xine

= 1.1.0
πŸ“¦
Xine

Xine

= 1.1.1
πŸ“¦
Xine

Xine

= 1.1.2
πŸ“¦
Xine

Xine

= 1.1.3
πŸ“¦
Xine

Xine

= 1.1.4
πŸ“¦
Xine

Xine

= 1.1.10.1
πŸ“¦
Xine

Xine

= 1.1.11
πŸ“¦
Xine

Xine

= 1.1.11.1

References & Advisories

Related Vulnerabilities