Divx develops media playback and encoding software spanning desktop players, web-based viewers, and codec infrastructure, positioning its products at the intersection of user-facing multimedia consumption and browser-based media delivery. The vulnerability profile centers on memory-safety and input-handling weaknesses—buffer-boundary violations and cross-site scripting flaws—characteristic of legacy multimedia codecs and web integration, and these disclosures tend to acquire public exploit tooling. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Divx over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-1912HIGH Stack-based buffer overflow in DivX Player 6.7 build 6.7.0.22 and earlier allows user-assisted remote attackers to cause a denial of service (application crash) or execute arbitrar | Apr 22, 2008 | 9.3 | 40 | NO | YES |
CVE-2008-0090MEDIUM A certain ActiveX control in npUpload.dll in DivX Player 6.6.0 allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long argument to the SetPasswo | Jan 4, 2008 | 5.0 | 32 | NO | YES |
CVE-2007-1294HIGH A certain ActiveX control in the DivXBrowserPlugin (npdivx32.dll) in DivX Web Player, as distributed with DivX Player 1.3.0, allows remote attackers to cause a denial of service (I | Mar 7, 2007 | 7.8 | 30 | NO | YES |
CVE-2008-5259HIGH Integer signedness error in DivX Web Player 1.4.2.7, and possibly earlier versions, allows remote attackers to execute arbitrary code via a DivX file containing a crafted Stream Fo | Apr 16, 2009 | 9.3 | 25 | NO | NO |
CVE-2007-0429MEDIUM DivXBrowserPlugin (aka DivX Web Player) npdivx32.dll, as distributed with DivX Player 6.4.1, allows remote attackers to cause a denial of service (Internet Explorer 7 crash) by inv | Jan 23, 2007 | 5.0 | 23 | NO | YES |
CVE-2008-1800MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in index.php in DivXDB 2002 0.94b allow remote attackers to inject arbitrary web script or HTML via the (1) choice, (2) _page_, | Apr 15, 2008 | 4.3 | 21 | NO | YES |
CVE-2014-10024HIGH Multiple integer signedness errors in DirectShowDemuxFilter, as used in Divx Web Player, Divx Player, and other Divx plugins, allow remote attackers to execute arbitrary code via a | Jan 13, 2015 | 7.5 | 20 | NO | NO |
CVE-2010-5232MEDIUM Untrusted search path vulnerability in DivX Plus Player 8.1.0 allows local users to gain privileges via a Trojan horse ssleay32.dll file in a certain directory. NOTE: the provenan | Sep 7, 2012 | 6.9 | 20 | NO | NO |
CVE-2010-5231MEDIUM Untrusted search path vulnerability in DivX Player 7.2.019 allows local users to gain privileges via a Trojan horse VersionCheckDLL.dll file in the current working directory, as de | Sep 7, 2012 | 6.9 | 19 | NO | NO |
CVE-2006-6444MEDIUM Stack-based buffer overflow in Nostra DivX Player 2.1, 2.2.00.0, and possibly earlier, allows remote attackers to execute arbitrary code via a long string in an M3U file. NOTE: Th | Dec 10, 2006 | 6.8 | 18 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Divx.
Media articles that mention a CVE ID that affects a product developed by Divx — matched by CVE ID, not by vendor name.