The Brandy Project maintains a focused product line centered on the Brandy application, which despite limited disclosure volume occupies a position of prominence within its operational domain. Its observed vulnerability surface recurs through memory-safety weakness classes, specifically out-of-bounds writes and classic buffer overflows, reflecting the low-level handling demands of its codebase. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Brandy Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-27372CRITICAL A buffer overflow vulnerability exists in Brandy Basic V Interpreter 1.21 in the run_interpreter function. | Oct 11, 2021 | 9.8 | 31 | NO | NO |
CVE-2019-14665MEDIUM Brandy 1.20.1 has a heap-based buffer overflow in define_array in variables.c via crafted BASIC source code. | Aug 5, 2019 | 5.5 | 20 | NO | NO |
CVE-2019-14662MEDIUM Brandy 1.20.1 has a stack-based buffer overflow in fileio_openout in fileio.c via crafted BASIC source code. | Aug 5, 2019 | 5.5 | 20 | NO | NO |
CVE-2019-14663MEDIUM Brandy 1.20.1 has a stack-based buffer overflow in fileio_openin in fileio.c via crafted BASIC source code. | Aug 5, 2019 | 5.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Brandy Project.
Media articles that mention a CVE ID that affects a product developed by Brandy Project — matched by CVE ID, not by vendor name.