Advancemame is a focused emulation and compression toolchain comprising the Advancemame arcade emulator and Advancecomp file-compression utility, positioned as niche retro-computing and software-maintenance tools. The recurring exposure in these products centers on memory-safety issues, including out-of-bounds reads and writes, heap-based buffer overflows, and improper input validation, typical of older codebases with legacy parsing and rendering logic that processes untrusted game ROM and compressed file formats. Live exploitation activity, severity distribution, and current exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Advancemame over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-1056HIGH An out-of-bounds heap buffer read flaw was found in the way advancecomp before 2.1-2018/02 handled processing of ZIP files. An attacker could potentially use this flaw to crash the | Jul 27, 2018 | 7.8 | 27 | NO | NO |
CVE-2020-23909HIGH Heap-based buffer over-read in function png_convert_4 in file pngex.cc in AdvanceMAME through 2.1. | Jul 18, 2023 | 7.1 | 24 | NO | NO |
CVE-2022-35014MEDIUM Advancecomp v2.3 contains a segmentation fault. | Aug 29, 2022 | 5.5 | 21 | NO | NO |
CVE-2022-35018MEDIUM Advancecomp v2.3 was discovered to contain a segmentation fault. | Aug 29, 2022 | 5.5 | 20 | NO | NO |
CVE-2022-35017MEDIUM Advancecomp v2.3 was discovered to contain a heap buffer overflow. | Aug 29, 2022 | 5.5 | 20 | NO | NO |
CVE-2022-35016MEDIUM Advancecomp v2.3 was discovered to contain a heap buffer overflow. | Aug 29, 2022 | 5.5 | 20 | NO | NO |
CVE-2022-35015MEDIUM Advancecomp v2.3 was discovered to contain a heap buffer overflow via le_uint32_read at /lib/endianrw.h. | Aug 29, 2022 | 5.5 | 20 | NO | NO |
CVE-2019-9210HIGH In AdvanceCOMP 2.1, png_compress in pngex.cc in advpng has an integer overflow upon encountering an invalid PNG size, which results in an attempted memcpy to write into a buffer th | Feb 27, 2019 | 7.8 | 20 | NO | NO |
CVE-2019-8383HIGH An issue was discovered in AdvanceCOMP through 2.1. An invalid memory address occurs in the function adv_png_unfilter_8 in lib/png.c. It can be triggered by sending a crafted file | Feb 17, 2019 | 7.8 | 20 | NO | NO |
CVE-2019-8379HIGH An issue was discovered in AdvanceCOMP through 2.1. A NULL pointer dereference exists in the function be_uint32_read() located in endianrw.h. It can be triggered by sending a craft | Feb 17, 2019 | 7.8 | 20 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Advancemame.
Media articles that mention a CVE ID that affects a product developed by Advancemame — matched by CVE ID, not by vendor name.