CVE-2004-1951
UnknownEPSS 8.10%
Last modified
CVE-2004-1951 is a vulnerability of currently unknown severity. xine 1.x alpha, 1.x beta, and 1.0rc through 1.0rc3a, and xine-ui 0.9.21 to 0.9.23 allows remote attackers to overwrite arbitrary files via the (1) audio.sun_audio_device or (2) dxr3.devicename options in an MRL link.. EPSS estimates a 8.10% chance of exploitation in the next 30 days.
Description
xine 1.x alpha, 1.x beta, and 1.0rc through 1.0rc3a, and xine-ui 0.9.21 to 0.9.23 allows remote attackers to overwrite arbitrary files via the (1) audio.sun_audio_device or (2) dxr3.devicename options in an MRL link.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Xine | Xine | 0.9.8 |
| Xine | Xine | 0.9.13 |
| Xine | Xine | 1_beta1 |
| Xine | Xine | 1_beta2 |
| Xine | Xine | 1_beta3 |
| Xine | Xine | 1_beta4 |
| Xine | Xine | 1_beta5 |
| Xine | Xine | 1_beta6 |
| Xine | Xine | 1_beta7 |
| Xine | Xine | 1_beta8 |
| Xine | Xine | 1_beta9 |
| Xine | Xine | 1_beta10 |
| Xine | Xine | 1_beta11 |
| Xine | Xine | 1_beta12 |
| Xine | Xine | 1_rc0a |
| Xine | Xine | 1_rc1 |
| Xine | Xine | 1_rc2 |
| Xine | Xine | 1_rc3 |
| Xine | Xine | 1_rc3a |
| Xine | Xine | 1_rc3b |
| Xine | Xine-Lib | 1_rc2 |
| Xine | Xine-Lib | 1_rc3a |
| Xine | Xine-Lib | 1_rc3b |
| Xine | Xine-Lib | 1_rc3c |
| Xine | Xine-Ui | 0.9.21 |
| Xine | Xine-Ui | 0.9.22 |
| Xine | Xine-Ui | 0.9.23 |
References
- http://www.securityfocus.com/bid/10193Exploit, Patch
- http://www.xinehq.de/index.php/security/XSA-2004-1Vendor Advisory
- http://www.xinehq.de/index.php/security/XSA-2004-2Vendor Advisory
- http://www.securityfocus.com/bid/10193Exploit, Patch
- http://www.xinehq.de/index.php/security/XSA-2004-1Vendor Advisory
- http://www.xinehq.de/index.php/security/XSA-2004-2Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2004-1951?
xine 1.x alpha, 1.x beta, and 1.0rc through 1.0rc3a, and xine-ui 0.9.21 to 0.9.23 allows remote attackers to overwrite arbitrary files via the (1) audio.sun_audio_device or (2) dxr3.devicename options in an MRL link.
How severe is CVE-2004-1951?
Severity scoring for CVE-2004-1951 is pending analysis. The EPSS model estimates a 8.10% probability of exploitation in the next 30 days.
How do I fix CVE-2004-1951?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2004
- CVE-2004-1945Buffer overflow in Kinesphere eXchange POP3 allows remote at…
- CVE-2004-1946Format string vulnerability in the PRINT_ERROR function in c…
- CVE-2004-1947The AVXSCANONLINE.AvxScanOnlineCtrl.1 ActiveX control in Bit…
- CVE-2004-1948NcFTP client 3.1.6 and 3.1.7, when the username and password…
- CVE-2004-1949SQL injection vulnerability in PostNuke 7.2.6 and earlier al…
- CVE-2004-1950phpBB 2.0.8a and earlier trusts the IP address that is in th…
- CVE-2004-1952SQL injection vulnerability in Advanced Guestbook 2.2 allows…
- CVE-2004-1953phProfession 2.5 allows remote attackers to gain sensitive i…
- CVE-2004-1954Cross-site scripting (XSS) vulnerability in modules.php in p…
- CVE-2004-1955SQL injection vulnerability in modules.php in phProfession 2…
- CVE-2004-1956PostNuke 0.7.2.6 allows remote attackers to gain information…
- CVE-2004-1957Multiple cross-site scripting (XSS) vulnerabilities in PostN…
Are you affected by CVE-2004-1951?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
