CVE-2008-5246

NONE EPSS 92.1%
Published Nov 26, 200817y ago · Modified Jun 16, 20262w ago
Find Similar
Published Nov 26, 2008 17y ago
Last Modified Jun 16, 2026 2w ago

Description

Multiple heap-based buffer overflows in xine-lib before 1.1.15 allow remote attackers to execute arbitrary code via vectors that send ID3 data to the (1) id3v22_interp_frame and (2) id3v24_interp_frame functions in src/demuxers/id3.c. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Threat Intelligence

EPSS Exploit Probability
92.1% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available

Weaknesses 1

CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer Memory Safety

Affected Products 48

VendorProductVersionRange
xinexine-lib* ≤1.1.14
xinexine-lib0.9.13any
xinexine-lib1any
xinexine-lib1any
xinexine-lib1any
xinexine-lib1any
xinexine-lib1any
xinexine-lib1any
xinexine-lib1any
xinexine-lib1any
xinexine-lib1any
xinexine-lib1any
xinexine-lib1any
xinexine-lib1any
xinexine-lib1any
xinexine-lib1.0any
xinexine-lib1.0.1any
xinexine-lib1.0.2any
xinexine-lib1.0.3aany
xinexine-lib1.1.0any
xinexine-lib1.1.1any
xinexine-lib1.1.2any
xinexine-lib1.1.3any
xinexine-lib1.1.4any
xinexine-lib1.1.5any
xinexine-lib1.1.6any
xinexine-lib1.1.7any
xinexine-lib1.1.8any
xinexine-lib1.1.9any
xinexine-lib1.1.9.1any
xinexine-lib1.1.10any
xinexine-lib1.1.10.1any
xinexine-lib1.1.11any
xinexine-lib1.1.11.1any
xinexine-lib1.1.12any
xinexine-lib1.1.13any
xinexine-lib1_beta1any
xinexine-lib1_beta2any
xinexine-lib1_beta3any
xinexine-lib1_beta4any
xinexine-lib1_beta5any
xinexine-lib1_beta6any
xinexine-lib1_beta7any
xinexine-lib1_beta8any
xinexine-lib1_beta9any
xinexine-lib1_beta10any
xinexine-lib1_beta11any
xinexine-lib1_beta12any

References 8

Remediation

No remediation data recorded yet

Check vendor advisories and the NVD entry for patch availability.