Cantata Project develops a music player and library-management application whose vulnerability exposure centers on input-validation and path-traversal weaknesses in file and playlist handling. These flaws reflect the attack surface inherent to a locally running audio application that parses user-supplied metadata and file paths. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cantata Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-12562CRITICAL An issue was discovered in the cantata-mounter D-Bus service in Cantata through 2.3.1. The wrapper script 'mount.cifs.wrapper' uses the shell to forward the arguments to the actual | Jun 19, 2018 | 9.8 | 31 | NO | NO |
CVE-2018-12561HIGH An issue was discovered in the cantata-mounter D-Bus service in Cantata through 2.3.1. A regular user can inject additional mount options such as file_mode= by manipulating (for ex | Jun 19, 2018 | 8.8 | 26 | NO | NO |
CVE-2018-12559HIGH An issue was discovered in the cantata-mounter D-Bus service in Cantata through 2.3.1. The mount target path check in mounter.cpp `mpOk()` is insufficient. A regular user can conse | Jun 19, 2018 | 8.8 | 26 | NO | NO |
CVE-2018-12560MEDIUM An issue was discovered in the cantata-mounter D-Bus service in Cantata through 2.3.1. Arbitrary unmounts can be performed by regular users via directory traversal sequences such a | Jun 19, 2018 | 6.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cantata Project.
Media articles that mention a CVE ID that affects a product developed by Cantata Project — matched by CVE ID, not by vendor name.