Open issues

CVE-2018-8831vulnerable (no DSA)A Persistent XSS vulnerability exists in Kodi (formerly XBMC) through ...
CVE-2017-8314vulnerable (no DSA)Directory Traversal in Zip Extraction built-in function in Kodi 17.1 a ...
CVE-2017-5982vulnerable (no DSA, ignored)Directory traversal vulnerability in the Chorus2 2.4.2 add-on for Kodi ...
CVE-2015-3885vulnerable (no DSA)Integer overflow in the ljpeg_start function in dcraw 7.00 and earlier ...
CVE-2014-3800vulnerable (no DSA)XBMC 13.0 uses world-readable permissions for .xbmc/userdata/sources.x ...

Open unimportant issues

CVE-2013-1438vulnerableUnspecified vulnerability in dcraw 0.8.x through 0.8.9, as used in lib ...

Resolved issues

CVE-2015-8367Memory objects are not intialized properly
CVE-2015-8366Index overflow in smal_decode_segment

Security announcements

DSA / DLADescription
DLA-1243-1xbmc - security update

