CyberSec.Space Logo
返回 CVE 瀏覽器

CVE-2008-5237

CRITICAL
10.0
CVSS Severity Score
EPSS Score0.0450%
EPSS Percentile11.69th
Published2008年11月26日
Last Modified2026年4月23日

Vulnerability Description

Multiple integer overflows in xine-lib 1.1.12, and other 1.1.15 and earlier versions, allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via (1) crafted width and height values that are not validated by the mymng_process_header function in demux_mng.c before use in an allocation calculation or (2) crafted current_atom_size and string_size values processed by the parse_reference_atom function in demux_qt.c for an RDRF_ATOM string.

Affected Platforms (CPE)

📦
Xine

Xine

<= 1.1.5
📦
Xine

Xine

= 0.9.13
📦
Xine

Xine

= 1
📦
Xine

Xine

= 1
📦
Xine

Xine

= 1
📦
Xine

Xine

= 1
📦
Xine

Xine

= 1
📦
Xine

Xine

= 1
📦
Xine

Xine

= 1
📦
Xine

Xine

= 1
📦
Xine

Xine

= 1
📦
Xine

Xine

= 1
📦
Xine

Xine

= 1
📦
Xine

Xine

= 1
📦
Xine

Xine

= 1
📦
Xine

Xine

= 1
📦
Xine

Xine

= 1
📦
Xine

Xine

= 1
📦
Xine

Xine

= 1
📦
Xine

Xine

= 1
📦
Xine

Xine

= 1
📦
Xine

Xine

= 1
📦
Xine

Xine

= 1
📦
Xine

Xine

= 1
📦
Xine

Xine

= 1
📦
Xine

Xine

= 1
📦
Xine

Xine

= 1
📦
Xine

Xine

= 1.0
📦
Xine

Xine

= 1.0.1
📦
Xine

Xine

= 1.0.2
📦
Xine

Xine

= 1.0.3a
📦
Xine

Xine

= 1.1.0
📦
Xine

Xine

= 1.1.1
📦
Xine

Xine

= 1.1.2
📦
Xine

Xine

= 1.1.3
📦
Xine

Xine

= 1.1.4
📦
Xine

Xine

= 1.1.10.1
📦
Xine

Xine

= 1.1.11
📦
Xine

Xine

= 1.1.11.1

References & Advisories

相關漏洞威脅