Skip to main content

Vendor/product archive

openmpt / libopenmpt CVEs

Beta · best-effort

11 CVEs tagged to openmpt / libopenmpt1 Critical, 4 High, 6 Medium, 0 Low, 0 Unrated.

CVE-2019-17113

Published Oct 4, 2019

In libopenmpt before 0.3.19 and 0.4.x before 0.4.9, ModPlug_InstrumentName and ModPlug_SampleName in libopenmpt_modplug.c do not restrict the lengths of libmodplug output-buffer s…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-14382

Published Jul 30, 2019

DSM in libopenmpt before 0.4.2 allows an assertion failure during file parsing with debug STLs.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20861

Published Jul 30, 2019

libopenmpt before 0.3.11 allows a crash with certain malformed custom tunings in MPTM files.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-14381

Published Jul 30, 2019

libopenmpt before 0.4.3 allows a crash due to a NULL pointer dereference when doing a portamento from an OPL instrument to an empty instrument note map slot.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-11710

Published Jun 4, 2018

soundlib/pattern.h in libopenmpt before 0.3.9 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted AMS…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-10017

Published Apr 11, 2018

soundlib/Snd_fx.cpp in OpenMPT before 1.27.07.00 and libopenmpt before 0.3.8 allows remote attackers to cause a denial of service (out-of-bounds read) via an IT or MO3 file with m…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-11311

Published Jul 17, 2017

soundlib/Load_psm.cpp in OpenMPT through 1.26.12.00 and libopenmpt before 0.2.8461-beta26 has a heap buffer overflow with the potential for arbitrary code execution via a crafted…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-11 of 11 CVEsPage 1 of 1