Xine is a media player library and application suite that, despite a narrow product portfolio, holds prominence in the vulnerability landscape due to its role in multimedia processing across Linux and open-source desktop environments. The vendor's exposure concentrates in its core libraries and user-facing applications such as xine-lib and the xine-ui frontend, and vulnerabilities affecting these products frequently acquire public exploit code. The recurring weakness classes—improper memory-buffer restrictions and input-validation flaws—reflect the inherent complexity of parsing and rendering untrusted multimedia formats, which present a durable attack surface for malformed or crafted media files. Defenders should treat media-player updates as a security priority, particularly in environments where users encounter untrusted audio or video content; current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xine over time
Signals from CVEs in this vendor scope (50 CVEs).
50 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-1300HIGH Buffer overflow in the open_aiff_file function in demux_aiff.c for xine-lib (libxine) 1-rc7 allows remote attackers to execute arbitrary code via a crafted AIFF file. | Jan 10, 2005 | 10.0 | 45 | NO | YES |
CVE-2008-1878HIGH Stack-based buffer overflow in the demux_nsf_send_chunk function in src/demuxers/demux_nsf.c in xine-lib 1.1.12 and earlier allows remote attackers to cause a denial of service (cr | Apr 17, 2008 | 7.5 | 35 | NO | YES |
CVE-2006-1905HIGH Multiple format string vulnerabilities in xiTK (xitk/main.c) in xine 0.99.3 allow remote attackers to execute arbitrary code via format string specifiers in a long filename on an E | Apr 20, 2006 | 7.5 | 35 | NO | YES |
CVE-2006-1664HIGH Buffer overflow in xine_list_delete_current in libxine 1.14 and earlier, as distributed in xine-lib 1.1.1 and earlier, allows remote attackers to execute arbitrary code via a craft | Apr 7, 2006 | 7.5 | 35 | NO | YES |
CVE-2008-0073MEDIUM Array index error in the sdpplin_parse function in input/libreal/sdpplin.c in xine-lib 1.1.10.1 allows remote RTSP servers to execute arbitrary code via a large streamid SDP parame | Mar 24, 2008 | 6.8 | 34 | NO | YES |
CVE-2008-0225MEDIUM Heap-based buffer overflow in the rmff_dump_cont function in input/libreal/rmff.c in xine-lib 1.1.9 and earlier allows remote attackers to execute arbitrary code via the SDP Abstra | Jan 10, 2008 | 6.4 | 32 | NO | YES |
CVE-2005-2967HIGH Format string vulnerability in input_cdda.c in xine-lib 1-beta through 1-beta 3, 1-rc, 1.0 through 1.0.2, and 1.1.1 allows remote servers to execute arbitrary code via format strin | Oct 14, 2005 | 7.5 | 32 | NO | YES |
CVE-2008-1110MEDIUM Buffer overflow in demuxers/demux_asf.c (aka the ASF demuxer) in the xineplug_dmx_asf.so plugin in xine-lib before 1.1.10 allows remote attackers to execute arbitrary code or cause | Feb 29, 2008 | 6.8 | 31 | NO | YES |
CVE-2004-1475MEDIUM Multiple stack-based buffer overflows in xine-lib 1-rc2 through 1-rc5 allow attackers to execute arbitrary code via (1) long VideoCD vcd:// MRLs or (2) long subtitle lines. | Dec 31, 2004 | 5.1 | 31 | NO | YES |
CVE-2008-1482MEDIUM Multiple integer overflows in xine-lib 1.1.11 and earlier allow remote attackers to trigger heap-based buffer overflows and possibly execute arbitrary code via (1) a crafted .FLV f | Mar 24, 2008 | 6.8 | 30 | NO | YES |
Signals from CVEs in this vendor scope (50 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xine.
Media articles that mention a CVE ID that affects a product developed by Xine — matched by CVE ID, not by vendor name.