← All CVEs

CVE-2006-1905

high · 7.5

Multiple format string vulnerabilities in xiTK (xitk/main.c) in xine 0.99.3 allow remote attackers to execute arbitrary code via format string specifiers in a long filename on an EXTINFO line in a playlist file.

7.5
CVSS
14.3%
EPSS (exploit prob.)
96th
EPSS percentile
2006-04-20
Published

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

VendorProductAffected versions
xinexine0.9.8
xinexine0.9.13
xinexine0.9.18
xinexine1.0
xinexine1.0.1
xinexine1_alpha
xinexine1_beta1
xinexine1_beta2
xinexine1_beta3
xinexine1_beta4
xinexine1_beta5
xinexine1_beta6
xinexine1_beta7
xinexine1_beta8
xinexine1_beta9
xinexine1_beta10
xinexine1_beta11
xinexine1_beta12
xinexine1_rc0
xinexine1_rc0a
xinexine1_rc1
xinexine1_rc2
xinexine1_rc3
xinexine1_rc3a
xinexine1_rc3b
xinexine1_rc4
xinexine1_rc5
xinexine1_rc6
xinexine1_rc6a
xinexine1_rc7
xinexine1_rc8

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2006-1905