Alsaplayer is a niche audio player application whose disclosed vulnerabilities center on memory-buffer handling issues within its core playback and codec-processing logic. The recurring weakness pattern reflects the low-level demands of audio stream parsing and direct memory manipulation characteristic of multimedia software. Current vulnerability counts, severity breakdown, and exploitation status are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Alsaplayer over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-5301MEDIUM Buffer overflow in the vorbis_stream_info function in input/vorbis/vorbis_engine.c (aka the vorbis input plugin) in AlsaPlayer before 0.99.80-rc3 allows remote attackers to execute | Oct 9, 2007 | 6.8 | 31 | NO | YES |
CVE-2002-1896HIGH Buffer overflow in Alsaplayer 0.99.71, when installed setuid root, allows local users to execute arbitrary code via a long (1) -f or (2) -o command line argument. | Dec 31, 2002 | 7.2 | 27 | NO | YES |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Alsaplayer.
Media articles that mention a CVE ID that affects a product developed by Alsaplayer — matched by CVE ID, not by vendor name.