CVE-2008-1878 describes a stack-based buffer overflow in the demux_nsf_send_chunk function within xine-lib versions 1.1.12 and earlier, affecting the xine media player. This vulnerability, with a CVSS score of 7.5 (High), allows remote unauthenticated attackers to cause a denial of service (application crash) and potentially execute arbitrary code by supplying a crafted, overly long NSF title. While not actively exploited in the wild and lacking Metasploit or Nuclei modules, a Proof-of-Concept exploit is available on ExploitDB, indicating its exploitability. Despite its age, the vulnerability has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.1.12CPE matchmatch criteria | cpe:2.3:a:xine:xine-lib:*:*:*:*:*:*:*:* | ||
1.1.0CPE matchmatch criteria | cpe:2.3:a:xine:xine-lib:1.1.0:*:*:*:*:*:*:* | ||
1.1.1CPE matchmatch criteria | cpe:2.3:a:xine:xine-lib:1.1.1:*:*:*:*:*:*:* | ||
1.1.9CPE matchmatch criteria | cpe:2.3:a:xine:xine-lib:1.1.9:*:*:*:*:*:*:* | ||
1.1.10CPE matchmatch criteria | cpe:2.3:a:xine:xine-lib:1.1.10:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.