Adplug Project maintains a niche audio-playback library focused on retro chiptune and tracker formats, which despite narrow deployment achieves prominence through its use in emulation, media software, and legacy game preservation contexts. Vulnerabilities affecting the library skew toward serious outcomes, with a meaningful share reaching critical severity and concentration in memory-safety issues such as out-of-bounds writes and double-free conditions that reflect the complexity of parsing untrusted audio files. Defenders should monitor this vendor's releases when integrating the library into applications that process untrusted input; live severity and exploitation status are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Adplug Project over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-15151CRITICAL AdPlug 2.3.1 has a double free in the Cu6mPlayer class in u6m.h. | Aug 18, 2019 | 9.8 | 31 | NO | NO |
CVE-2018-17825CRITICAL An issue was discovered in AdPlug 2.3.1. There are several double-free vulnerabilities in the CEmuopl class in emuopl.cpp because of a destructor's two OPLDestroy calls, each of wh | Oct 1, 2018 | 9.8 | 31 | NO | NO |
CVE-2019-14734HIGH AdPlug 2.3.1 has multiple heap-based buffer overflows in CmtkLoader::load() in mtk.cpp. | Aug 7, 2019 | 8.8 | 28 | NO | NO |
CVE-2019-14733HIGH AdPlug 2.3.1 has multiple heap-based buffer overflows in CradLoader::load() in rad.cpp. | Aug 7, 2019 | 8.8 | 27 | NO | NO |
CVE-2019-14732HIGH AdPlug 2.3.1 has multiple heap-based buffer overflows in Ca2mLoader::load() in a2m.cpp. | Aug 7, 2019 | 8.8 | 27 | NO | NO |
CVE-2019-14692HIGH AdPlug 2.3.1 has a heap-based buffer overflow in CmkjPlayer::load() in mkj.cpp. | Aug 6, 2019 | 8.8 | 27 | NO | NO |
CVE-2019-14691HIGH AdPlug 2.3.1 has a heap-based buffer overflow in CdtmLoader::load() in dtm.cpp. | Aug 6, 2019 | 8.8 | 27 | NO | NO |
CVE-2019-14690HIGH AdPlug 2.3.1 has a heap-based buffer overflow in CxadbmfPlayer::__bmf_convert_stream() in bmf.cpp. | Aug 6, 2019 | 8.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Adplug Project.
Media articles that mention a CVE ID that affects a product developed by Adplug Project — matched by CVE ID, not by vendor name.