// For flags

CVE-2008-5237

 

Severity Score

10.0
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Multiple integer overflows in xine-lib 1.1.12, and other 1.1.15 and earlier versions, allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via (1) crafted width and height values that are not validated by the mymng_process_header function in demux_mng.c before use in an allocation calculation or (2) crafted current_atom_size and string_size values processed by the parse_reference_atom function in demux_qt.c for an RDRF_ATOM string.

Múltiples desbordamientos de entero en xine-lib 1.1.12, y otros 1.1.15 y versiones anteriores, permiten a atacantes remotos provocar una denegación de servicio (caída) o posiblemente ejecutar código de su elección mediante (1) valores de altura y anchura manipulados que no se validan por al función mymng_process_header en demux_mng.c antes de usarse en un cálculo de asignación o (2)valores current_atom_size y string_size manipulados procesados por la función arse_reference_atom en demux_qt.c.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2008-11-25 CVE Reserved
  • 2008-11-26 CVE Published
  • 2023-03-07 EPSS Updated
  • 2024-08-07 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-189: Numeric Errors
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Xine
Search vendor "Xine"
Xine
Search vendor "Xine" for product "Xine"
<= 1.1.5
Search vendor "Xine" for product "Xine" and version " <= 1.1.5"
-
Affected
Xine
Search vendor "Xine"
Xine
Search vendor "Xine" for product "Xine"
0.9.13
Search vendor "Xine" for product "Xine" and version "0.9.13"
-
Affected
Xine
Search vendor "Xine"
Xine
Search vendor "Xine" for product "Xine"
1
Search vendor "Xine" for product "Xine" and version "1"
beta1
Affected
Xine
Search vendor "Xine"
Xine
Search vendor "Xine" for product "Xine"
1
Search vendor "Xine" for product "Xine" and version "1"
beta10
Affected
Xine
Search vendor "Xine"
Xine
Search vendor "Xine" for product "Xine"
1
Search vendor "Xine" for product "Xine" and version "1"
beta11
Affected
Xine
Search vendor "Xine"
Xine
Search vendor "Xine" for product "Xine"
1
Search vendor "Xine" for product "Xine" and version "1"
beta12
Affected
Xine
Search vendor "Xine"
Xine
Search vendor "Xine" for product "Xine"
1
Search vendor "Xine" for product "Xine" and version "1"
beta2
Affected
Xine
Search vendor "Xine"
Xine
Search vendor "Xine" for product "Xine"
1
Search vendor "Xine" for product "Xine" and version "1"
beta3
Affected
Xine
Search vendor "Xine"
Xine
Search vendor "Xine" for product "Xine"
1
Search vendor "Xine" for product "Xine" and version "1"
beta4
Affected
Xine
Search vendor "Xine"
Xine
Search vendor "Xine" for product "Xine"
1
Search vendor "Xine" for product "Xine" and version "1"
beta5
Affected
Xine
Search vendor "Xine"
Xine
Search vendor "Xine" for product "Xine"
1
Search vendor "Xine" for product "Xine" and version "1"
beta6
Affected
Xine
Search vendor "Xine"
Xine
Search vendor "Xine" for product "Xine"
1
Search vendor "Xine" for product "Xine" and version "1"
beta7
Affected
Xine
Search vendor "Xine"
Xine
Search vendor "Xine" for product "Xine"
1
Search vendor "Xine" for product "Xine" and version "1"
beta8
Affected
Xine
Search vendor "Xine"
Xine
Search vendor "Xine" for product "Xine"
1
Search vendor "Xine" for product "Xine" and version "1"
beta9
Affected
Xine
Search vendor "Xine"
Xine
Search vendor "Xine" for product "Xine"
1
Search vendor "Xine" for product "Xine" and version "1"
rc0a
Affected
Xine
Search vendor "Xine"
Xine
Search vendor "Xine" for product "Xine"
1
Search vendor "Xine" for product "Xine" and version "1"
rc1
Affected
Xine
Search vendor "Xine"
Xine
Search vendor "Xine" for product "Xine"
1
Search vendor "Xine" for product "Xine" and version "1"
rc2
Affected
Xine
Search vendor "Xine"
Xine
Search vendor "Xine" for product "Xine"
1
Search vendor "Xine" for product "Xine" and version "1"
rc3
Affected
Xine
Search vendor "Xine"
Xine
Search vendor "Xine" for product "Xine"
1
Search vendor "Xine" for product "Xine" and version "1"
rc3a
Affected
Xine
Search vendor "Xine"
Xine
Search vendor "Xine" for product "Xine"
1
Search vendor "Xine" for product "Xine" and version "1"
rc3b
Affected
Xine
Search vendor "Xine"
Xine
Search vendor "Xine" for product "Xine"
1
Search vendor "Xine" for product "Xine" and version "1"
rc3c
Affected
Xine
Search vendor "Xine"
Xine
Search vendor "Xine" for product "Xine"
1
Search vendor "Xine" for product "Xine" and version "1"
rc4
Affected
Xine
Search vendor "Xine"
Xine
Search vendor "Xine" for product "Xine"
1
Search vendor "Xine" for product "Xine" and version "1"
rc4a
Affected
Xine
Search vendor "Xine"
Xine
Search vendor "Xine" for product "Xine"
1
Search vendor "Xine" for product "Xine" and version "1"
rc5
Affected
Xine
Search vendor "Xine"
Xine
Search vendor "Xine" for product "Xine"
1
Search vendor "Xine" for product "Xine" and version "1"
rc6a
Affected
Xine
Search vendor "Xine"
Xine
Search vendor "Xine" for product "Xine"
1
Search vendor "Xine" for product "Xine" and version "1"
rc7
Affected
Xine
Search vendor "Xine"
Xine
Search vendor "Xine" for product "Xine"
1
Search vendor "Xine" for product "Xine" and version "1"
rc8
Affected
Xine
Search vendor "Xine"
Xine
Search vendor "Xine" for product "Xine"
1.0
Search vendor "Xine" for product "Xine" and version "1.0"
-
Affected
Xine
Search vendor "Xine"
Xine
Search vendor "Xine" for product "Xine"
1.0.1
Search vendor "Xine" for product "Xine" and version "1.0.1"
-
Affected
Xine
Search vendor "Xine"
Xine
Search vendor "Xine" for product "Xine"
1.0.2
Search vendor "Xine" for product "Xine" and version "1.0.2"
-
Affected
Xine
Search vendor "Xine"
Xine
Search vendor "Xine" for product "Xine"
1.0.3a
Search vendor "Xine" for product "Xine" and version "1.0.3a"
-
Affected
Xine
Search vendor "Xine"
Xine
Search vendor "Xine" for product "Xine"
1.1.0
Search vendor "Xine" for product "Xine" and version "1.1.0"
-
Affected
Xine
Search vendor "Xine"
Xine
Search vendor "Xine" for product "Xine"
1.1.1
Search vendor "Xine" for product "Xine" and version "1.1.1"
-
Affected
Xine
Search vendor "Xine"
Xine
Search vendor "Xine" for product "Xine"
1.1.2
Search vendor "Xine" for product "Xine" and version "1.1.2"
-
Affected
Xine
Search vendor "Xine"
Xine
Search vendor "Xine" for product "Xine"
1.1.3
Search vendor "Xine" for product "Xine" and version "1.1.3"
-
Affected
Xine
Search vendor "Xine"
Xine
Search vendor "Xine" for product "Xine"
1.1.4
Search vendor "Xine" for product "Xine" and version "1.1.4"
-
Affected
Xine
Search vendor "Xine"
Xine
Search vendor "Xine" for product "Xine"
1.1.10.1
Search vendor "Xine" for product "Xine" and version "1.1.10.1"
-
Affected
Xine
Search vendor "Xine"
Xine
Search vendor "Xine" for product "Xine"
1.1.11
Search vendor "Xine" for product "Xine" and version "1.1.11"
-
Affected
Xine
Search vendor "Xine"
Xine
Search vendor "Xine" for product "Xine"
1.1.11.1
Search vendor "Xine" for product "Xine" and version "1.1.11.1"
-
Affected