The Beep Project maintains a narrowly scoped audio-processing tool where its disclosed vulnerabilities cluster around concurrency and file-system access issues, specifically race conditions in shared-resource handling and path-traversal weaknesses in directory access controls. These weakness patterns reflect the product's core function and the synchronization and input-validation demands of audio file manipulation; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Beep Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-0492HIGH Johnathan Nightingale beep through 1.3.4, if setuid, has a race condition that allows local privilege escalation. | Apr 3, 2018 | 7.0 | 35 | NO | YES |
CVE-2018-1000532MEDIUM beep version 1.3 and up contains a External Control of File Name or Path vulnerability in --device option that can result in Local unprivileged user can inhibit execution of arbitr | Jun 26, 2018 | 4.7 | 16 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Beep Project.
Media articles that mention a CVE ID that affects a product developed by Beep Project — matched by CVE ID, not by vendor name.