AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2008-5237

HIGH · CVSS 10 EPSS 5.55%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2008-11-26 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2008-5237
Severity
HIGH
CVSS
10
EPSS
5.55%

Original NVD Description

Multiple integer overflows in xine-lib 1.1.12, and other 1.1.15 and earlier versions, allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via (1) crafted width and height values that are not validated by the mymng_process_header function in demux_mng.c before use in an allocation calculation or (2) crafted current_atom_size and string_size values processed by the parse_reference_atom function in demux_qt.c for an RDRF_ATOM string.