Search: "xine"

70 CVEs found

xinetd 2.1.8.x does not properly restrict connections if hostnames are used for access control and the connecting host does not have a reverse DNS entry.

Published: 2000-06-04
Products: 9
Vendors:
xinetd

xinetd 2.1.8 and earlier runs with a default umask of 0, which could allow local users to read or modify files that are created by an application that runs under xinetd but does not set its own safe u...

Published: 2001-07-10
Products: 16
Vendors:
xinetd

Multiple vulnerabilities in xinetd 2.3.0 and earlier, and additional variants until 2.3.3, may allow remote attackers to cause a denial of service or execute arbitrary code, primarily via buffer overf...

Published: 2001-08-29
Products: 16
Vendors:
xinetd

Buffer overflow in Linux xinetd 2.1.8.9pre11-1 and earlier may allow remote attackers to execute arbitrary code via a long ident response, which is not properly handled by the svc_logprint function.

Published: 2001-10-18
Products: 9
Vendors:
debian suse
CVE-2001-0825
10.0 HIGH

Buffer overflow in internal string handling routines of xinetd before 2.1.8.8 allows remote attackers to execute arbitrary commands via a length argument of zero or less, which disables the length che...

Published: 2001-12-06
Products: 4
Vendors:
xinetd

xkas in Xinet K-AShare 0.011.01 for IRIX allows local users to read arbitrary files via a symlink attack on the VOLICON file, which is copied to the .HSicon file in a shared directory.

Published: 2002-05-16
Products: 17
Vendors:
xinet sgi

xinetd 2.3.4 leaks file descriptors for the signal pipe to services that are launched by xinetd, which could allow those services to cause a denial of service via the pipe.

Published: 2002-09-05
Products: 3
Vendors:
xinetd

gds_lock_mgr in Borland InterBase allows local users to overwrite files and gain privileges via a symlink attack on a "isc_init1.X" temporary file, as demonstrated by modifying the xinetdbd file.

Published: 2003-04-02
Products: 4
Vendors:
borland_software
CVE-2003-0211
5.0 MEDIUM

Memory leak in xinetd 2.3.10 allows remote attackers to cause a denial of service (memory consumption) via a large number of rejected connections.

Published: 2003-05-05
Products: 11
Vendors:
xinetd

xine allows local users to overwrite arbitrary files via a symlink attack on a bug report email that is generated by the (1) xine-bugreport or (2) xine-check scripts.

Published: 2004-04-15
Products: 19
Vendors:
xine
CVE-2004-0433
10.0 HIGH

Multiple buffer overflows in the Real-Time Streaming Protocol (RTSP) client for (1) MPlayer before 1.0pre4 and (2) xine lib (xine-lib) before 1-rc4, when playing Real RTSP (realrtsp) streams, allow re...

Published: 2004-08-18
Products: 16
Vendors:
xine mplayer

Heap-based buffer overflow in the DVD subpicture decoder in xine xine-lib 1-rc5 and earlier allows remote attackers to execute arbitrary code via a (1) DVD or (2) MPEG subpicture header where the seco...

Published: 2004-09-16
Products: 41
Vendors:
xine
CVE-2004-1455
5.1 MEDIUM

Stack-based buffer overflow in Xine-lib-rc5 in xine-lib 1_rc5-r2 and earlier allows remote attackers to execute arbitrary code via crafted playlists that result in a long vcd:// URL.

Published: 2004-12-31
Products: 18
Vendors:
xine
CVE-2004-1475
5.1 MEDIUM

Multiple stack-based buffer overflows in xine-lib 1-rc2 through 1-rc5 allow attackers to execute arbitrary code via (1) long VideoCD vcd:// MRLs or (2) long subtitle lines.

Published: 2004-12-31
Products: 10
Vendors:
xine
CVE-2004-1476
5.1 MEDIUM

Stack-based buffer overflow in the VideoCD (VCD) code in xine-lib 1-rc2 through 1-rc5, as derived from libcdio, allows attackers to execute arbitrary code via a VideoCD with an unterminated disk label...

Published: 2004-12-31
Products: 17
Vendors:
xine suse
CVE-2004-1951
5.0 MEDIUM

xine 1.x alpha, 1.x beta, and 1.0rc through 1.0rc3a, and xine-ui 0.9.21 to 0.9.23 allows remote attackers to overwrite arbitrary files via the (1) audio.sun_audio_device or (2) dxr3.devicename options...

Published: 2004-12-31
Products: 27
Vendors:
xine
CVE-2004-1187
10.0 HIGH

Heap-based buffer overflow in the pnm_get_chunk function for xine 0.99.2, and other packages such as MPlayer that use the same code, allows remote attackers to execute arbitrary code via long PNA_TAG ...

Published: 2005-01-10
Products: 78
Vendors:
xine mplayer mandrakesoft
CVE-2004-1188
10.0 HIGH

The pnm_get_chunk function in xine 0.99.2 and earlier, and other packages such as MPlayer that use the same code, does not properly verify that the chunk size is less than the PREAMBLE_SIZE, which cau...

Published: 2005-01-10
Products: 78
Vendors:
xine mplayer mandrakesoft
CVE-2004-1300
10.0 HIGH

Buffer overflow in the open_aiff_file function in demux_aiff.c for xine-lib (libxine) 1-rc7 allows remote attackers to execute arbitrary code via a crafted AIFF file.

Published: 2005-01-10
Products: 1
Vendors:
xine

Multiple heap-based buffer overflows in the code used to handle (1) MMS over TCP (MMST) streams or (2) RealMedia RTSP streams in xine-lib before 1.0, and other products that use xine-lib such as MPlay...

Published: 2005-05-02
Products: 16
Vendors:
xine mplayer