AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2008-5242

MEDIUM · CVSS 6.8 EPSS 3.14%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2008-11-26 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2008-5242
Severity
MEDIUM
CVSS
6.8
EPSS
3.14%

Original NVD Description

demux_qt.c in xine-lib 1.1.12, and other 1.1.15 and earlier versions, does not validate the count field before calling calloc for STSD_ATOM atom allocation, which allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted media file.