Abcm2ps is a specialized music-notation conversion tool that translates ABC text format into PostScript and other formats, with its vulnerability footprint concentrated in a single product focused on file parsing and rendering. The durable signal is rooted in out-of-bounds read and write conditions that arise during the parsing and processing of music notation data, reflecting memory-safety challenges inherent to format conversion utilities. Current severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Abcm2ps Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-32436MEDIUM An out-of-bounds read in the function write_title() in subs.c of abcm2ps v8.14.11 allows remote attackers to cause a Denial of Service (DoS) via unspecified vectors. | Mar 10, 2022 | 6.5 | 23 | NO | NO |
CVE-2021-32435MEDIUM Stack-based buffer overflow in the function get_key in parse.c of abcm2ps v8.14.11 allows remote attackers to cause a Denial of Service (DoS) via unspecified vectors. | Mar 10, 2022 | 5.5 | 21 | NO | NO |
CVE-2021-32434MEDIUM abcm2ps v8.14.11 was discovered to contain an out-of-bounds read in the function calculate_beam at draw.c. | Mar 10, 2022 | 5.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Abcm2ps Project.
Media articles that mention a CVE ID that affects a product developed by Abcm2ps Project — matched by CVE ID, not by vendor name.