Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Xine

First CVE: Apr 15, 2004Active for: 22 yearsTotal CVEs: 50
50.2
VTI Score
TOP TARGET

Xine is a media player library and application suite that, despite a narrow product portfolio, holds prominence in the vulnerability landscape due to its role in multimedia processing across Linux and open-source desktop environments. The vendor's exposure concentrates in its core libraries and user-facing applications such as xine-lib and the xine-ui frontend, and vulnerabilities affecting these products frequently acquire public exploit code. The recurring weakness classes—improper memory-buffer restrictions and input-validation flaws—reflect the inherent complexity of parsing and rendering untrusted multimedia formats, which present a durable attack surface for malformed or crafted media files. Defenders should treat media-player updates as a security priority, particularly in environments where users encounter untrusted audio or video content; current exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
50
Total CVEs
More Total CVEs than 98% of tracked vendors
1.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 76% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 50% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Xine over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 15, 2004
22 years ago
Most Recent CVE
Apr 8, 2009
6,316 days ago

Products(6 total)

Top CVEs

Signals from CVEs in this vendor scope (50 CVEs).

50 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2004-1300HIGH
Buffer overflow in the open_aiff_file function in demux_aiff.c for xine-lib (libxine) 1-rc7 allows remote attackers to execute arbitrary code via a crafted AIFF file.
Jan 10, 200510.045NOYES
CVE-2008-1878HIGH
Stack-based buffer overflow in the demux_nsf_send_chunk function in src/demuxers/demux_nsf.c in xine-lib 1.1.12 and earlier allows remote attackers to cause a denial of service (cr
Apr 17, 20087.535NOYES
CVE-2006-1905HIGH
Multiple format string vulnerabilities in xiTK (xitk/main.c) in xine 0.99.3 allow remote attackers to execute arbitrary code via format string specifiers in a long filename on an E
Apr 20, 20067.535NOYES
CVE-2006-1664HIGH
Buffer overflow in xine_list_delete_current in libxine 1.14 and earlier, as distributed in xine-lib 1.1.1 and earlier, allows remote attackers to execute arbitrary code via a craft
Apr 7, 20067.535NOYES
CVE-2008-0073MEDIUM
Array index error in the sdpplin_parse function in input/libreal/sdpplin.c in xine-lib 1.1.10.1 allows remote RTSP servers to execute arbitrary code via a large streamid SDP parame
Mar 24, 20086.834NOYES
CVE-2008-0225MEDIUM
Heap-based buffer overflow in the rmff_dump_cont function in input/libreal/rmff.c in xine-lib 1.1.9 and earlier allows remote attackers to execute arbitrary code via the SDP Abstra
Jan 10, 20086.432NOYES
CVE-2005-2967HIGH
Format string vulnerability in input_cdda.c in xine-lib 1-beta through 1-beta 3, 1-rc, 1.0 through 1.0.2, and 1.1.1 allows remote servers to execute arbitrary code via format strin
Oct 14, 20057.532NOYES
CVE-2008-1110MEDIUM
Buffer overflow in demuxers/demux_asf.c (aka the ASF demuxer) in the xineplug_dmx_asf.so plugin in xine-lib before 1.1.10 allows remote attackers to execute arbitrary code or cause
Feb 29, 20086.831NOYES
CVE-2004-1475MEDIUM
Multiple stack-based buffer overflows in xine-lib 1-rc2 through 1-rc5 allow attackers to execute arbitrary code via (1) long VideoCD vcd:// MRLs or (2) long subtitle lines.
Dec 31, 20045.131NOYES
CVE-2008-1482MEDIUM
Multiple integer overflows in xine-lib 1.1.11 and earlier allow remote attackers to trigger heap-based buffer overflows and possibly execute arbitrary code via (1) a crafted .FLV f
Mar 24, 20086.830NOYES
View all 50 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products50 CVEs
42%
56%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown50 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown50 (100.0%)
User Interaction
None0 (0.0%)
Unknown50 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown50 (100.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (50 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
13 CVEs
26.0% of CVEs· 78th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Xine.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Xine — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Xine's Products

View all 3 CNAs →

Top CWEs