Search CVE reports


Toggle filters

1 – 10 of 11 results


CVE-2019-17113

Medium priority
Vulnerable

In libopenmpt before 0.3.19 and 0.4.x before 0.4.9, ModPlug_InstrumentName and ModPlug_SampleName in libopenmpt_modplug.c do not restrict the lengths of libmodplug output-buffer strings in the C API, leading to a buffer overflow.

1 affected package

libopenmpt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libopenmpt Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2019-14383

Medium priority
Vulnerable

J2B in libopenmpt before 0.4.2 allows an assertion failure during file parsing with debug STLs.

1 affected package

libopenmpt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libopenmpt Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2019-14382

Low priority
Vulnerable

DSM in libopenmpt before 0.4.2 allows an assertion failure during file parsing with debug STLs.

1 affected package

libopenmpt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libopenmpt Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2019-14380

Low priority
Vulnerable

libopenmpt before 0.4.5 allows a crash during playback due to an out-of-bounds read in XM and MT2 files.

1 affected package

libopenmpt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libopenmpt Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2018-20861

Medium priority
Vulnerable

libopenmpt before 0.3.11 allows a crash with certain malformed custom tunings in MPTM files.

1 affected package

libopenmpt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libopenmpt Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2018-20860

Low priority
Vulnerable

libopenmpt before 0.3.13 allows a crash with malformed MED files.

1 affected package

libopenmpt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libopenmpt Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2019-14381

Low priority
Not affected

libopenmpt before 0.4.3 allows a crash due to a NULL pointer dereference when doing a portamento from an OPL instrument to an empty instrument note map slot.

1 affected package

libopenmpt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libopenmpt Not affected
Show less packages

CVE-2018-11710

Medium priority

Some fixes available 1 of 2

soundlib/pattern.h in libopenmpt before 0.3.9 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted AMS file because of an invalid write near address 0 in...

1 affected package

libopenmpt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libopenmpt Not affected Not affected Fixed
Show less packages

CVE-2018-10017

Low priority

Some fixes available 1 of 2

soundlib/Snd_fx.cpp in OpenMPT before 1.27.07.00 and libopenmpt before 0.3.8 allows remote attackers to cause a denial of service (out-of-bounds read) via an IT or MO3 file with many nested pattern loops.

1 affected package

libopenmpt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libopenmpt Not affected Not affected Fixed
Show less packages

CVE-2018-6611

Medium priority
Ignored

soundlib/Load_stp.cpp in OpenMPT through 1.27.04.00, and libopenmpt before 0.3.6, has an out-of-bounds read via a malformed STP file.

1 affected package

libopenmpt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libopenmpt Not affected
Show less packages