peter bassill · operator
$ cve CVE-2006-2230 JSON

CVE-2006-2230 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 7.1% (pctl 94)

Patch early

A public exploit exists.

Description

Multiple format string vulnerabilities in xiTK (xitk/main.c) in xine 0.99.4 might allow attackers to cause a denial of service via format string specifiers in an MP3 filename specified on the command line. NOTE: this is a different vulnerability than CVE-2006-1905. In addition, if the only attack vectors involve a user-assisted, local command line argument of a non-setuid program, this issue might not be a vulnerability.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
EPSS7.1% — more likely to be exploited than 94% of all CVEs
On CISA KEVno
Public exploityes
Published2006-05-05
Last modified2026-06-16

Affected (1)

VendorProduct
xinexine

Public exploits

SourceTitleDate
exploit-dbXine 0.99.x - Filename Handling Remote Format String2006-05-01

References

→ the Explorer  ·  watch your stack  ·  NVD