2 results (0.003 seconds)

CVSS: 10.0EPSS: 2%CPEs: 1EXPL: 0

Format string vulnerability in the errors_create_window function in errors.c in xine-ui allows attackers to execute arbitrary code via unknown vectors. Vulnerabilidad de cadena de formato en la función errors_create_window en errors.c de xine-ui permite a atacantes remotos ejecutar código de su elección mediante vectores no especificados. • http://osvdb.org/31594 http://secunia.com/advisories/23709 http://secunia.com/advisories/23891 http://secunia.com/advisories/23931 http://security.gentoo.org/glsa/glsa-200701-18.xml http://www.mandriva.com/security/advisories?name=MDKSA-2007:027 http://www.mandriva.com/security/advisories?name=MDKSA-2007:154 http://www.securityfocus.com/archive/1/456590/100/0/threaded http://www.securityfocus.com/bid/22002 https://exchange.xforce.ibmcloud.com/vulnerabilities/31505 •

CVSS: 5.0EPSS: 0%CPEs: 27EXPL: 2

xine 1.x alpha, 1.x beta, and 1.0rc through 1.0rc3a, and xine-ui 0.9.21 to 0.9.23 allows remote attackers to overwrite arbitrary files via the (1) audio.sun_audio_device or (2) dxr3.devicename options in an MRL link. • https://www.exploit-db.com/exploits/24038 http://secunia.com/advisories/11433 http://security.gentoo.org/glsa/glsa-200404-20.xml http://www.osvdb.org/5594 http://www.osvdb.org/5739 http://www.securityfocus.com/bid/10193 http://www.slackware.com/security/viewer.php?l=slackware-security&y=2004&m=slackware-security.372791 http://www.xinehq.de/index.php/security/XSA-2004-1 http://www.xinehq.de/index.php/security/XSA-2004-2 https://exchange.xforce.ibmcloud.com/vulnerabi •