Format string vulnerability in gxine 0.4.1 through 0.4.4, and other versions down to 0.3, allows remote attackers to execute arbitrary code via a ram file with a URL whose hostname contains format string specifiers.
http://www.vupen.com/english/advisories/2005/0626
http://www.securityfocus.com/bid/13707
http://www.0xbadexworm.org/adv/gxinefmt.txt
http://security.gentoo.org/glsa/glsa-200505-19.xml
http://secunia.com/advisories/15451