CVE-2025-71264 describes an out-of-bounds array access vulnerability in Mumble versions before 1.6.870, which can result in a client crash, leading to a denial of service. This issue carries a low CVSS score of 3.7, primarily due to its high attack complexity despite requiring no privileges or user interaction. There is currently no evidence of active exploitation, public exploit code, or significant community attention, with media coverage limited to vendor security advisories.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 1.6.870CPE match | cpe:2.3:a:mumble:mumble:*:*:*:*:*:*:*:* | ||
< 1.6.870CPE matchmatch criteria | cpe:2.3:a:mumble:mumble:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.