See how mplayerhq compares to other vendors in security performance
Mplayer SVN-r38374-13.0.1 is vulnerable to Memory Leak via vf.c and vfvo.c.
Certain The MPlayer Project products are vulnerable to Buffer Overflow via function asfinitaudiostream() of libmpdemux/asfheader.c. This affects mplayer SVN-r38374-13.0.1 and mencoder SVN-r38374-13.0.1.
Certain The MPlayer Project products are vulnerable to Buffer Overflow via function movbuildindex() of libmpdemux/demuxmov.c. This affects mplayer SVN-r38374-13.0.1 and mencoder SVN-r38374-13.0.1.
Certain The MPlayer Project products are vulnerable to Buffer Overflow via function play() of libaf/af.c:639. This affects mplayer SVN-r38374-13.0.1 and mencoder SVN-r38374-13.0.1.
Certain The MPlayer Project products are vulnerable to Buffer Overflow via readaviheader() of libmpdemux/aviheader.c . This affects mplayer SVN-r38374-13.0.1 and mencoder SVN-r38374-13.0.1.
Certain The MPlayer Project products are vulnerable to Buffer Overflow via function genshvideo () of mplayer/libmpdemux/demuxmov.c. This affects mplayer SVN-r38374-13.0.1 and mencoder SVN-r38374-13.0.1.
The MPlayer Project mencoder SVN-r38374-13.0.1 is vulnerable to Divide By Zero via the function config () of llibmpcodecs/vfscale.c.
Certain The MPlayer Project products are vulnerable to Buffer Overflow via function mpgetbits() of libmpdemux/mpeghdr.c which affects mencoder and mplayer. This affects mecoder SVN-r38374-13.0.1 and mplayer SVN-r38374-13.0.1.
Certain The MPlayer Project products are vulnerable to Buffer Overflow via function movbuildindex() of libmpdemux/demuxmov.c. This affects mplayer SVN-r38374-13.0.1 and mencoder SVN-r38374-13.0.1.
Certain The MPlayer Project products are vulnerable to Out-of-bounds Read via function readmetarecord() of mplayer/libmpdemux/asfheader.c. This affects mplayer SVN-r38374-13.0.1 and mencoder SVN-r38374-13.0.1.
Certain The MPlayer Project products are vulnerable to Divide By Zero via the function demuxavireadpacket of libmpdemux/demuxavi.c. This affects mplyer SVN-r38374-13.0.1 and mencoder SVN-r38374-13.0.1.
Certain The MPlayer Project products are vulnerable to Divide By Zero via function demuxopenavi() of libmpdemux/demuxavi.c which affects mencoder. This affects mplayer SVN-r38374-13.0.1 and mencoder SVN-r38374-13.0.1.
Certain The MPlayer Project products are vulnerable to Buffer Overflow via the function mpunescape03() of libmpdemux/mpeghdr.c. This affects mencoder SVN-r38374-13.0.1 and mplayer SVN-r38374-13.0.1.
The MPlayer Project mplayer SVN-r38374-13.0.1 is vulnerable to memory corruption via function freempimage() of libmpcodecs/mpimage.c.
The MPlayer Project v1.5 was discovered to contain a heap use-after-free resulting in a double free in the preinit function at libvo/vov4l2.c. This vulnerability can lead to a Denial of Service (DoS) via a crafted file. The device=strdup statement is not executed on every call.
FFmpeg before 0.5.4, as used in MPlayer and other products, allows remote attackers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via a malformed RealMedia file.
Multiple unspecified vulnerabilities in FFmpeg 0.4.x through 0.6.x, as used in MPlayer 1.0 and other products, in Mandriva Linux 2009.0, 2010.0, and 2010.1; Corporate Server 4.0 (aka CS4.0); and Mandriva Enterprise Server 5 (aka MES5) have unknown impact and attack vectors, related to issues "originally discovered by Google Chrome developers."
The VC-1 decoding functionality in FFmpeg before 0.5.4, as used in MPlayer and other products, does not properly restrict read operations, which allows remote attackers to have an unspecified impact via a crafted VC-1 file, a related issue to CVE-2011-0723.
FFmpeg before 0.5.4, as used in MPlayer and other products, allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a malformed WMV file.
flicvideo.c in libavcodec 0.6 and earlier in FFmpeg, as used in MPlayer and other products, allows remote attackers to execute arbitrary code via a crafted flic file, related to an "arbitrary offset dereference vulnerability."