Csounds is a niche audio digital signal processing engine and music synthesis language whose vulnerability footprint centers on its core Csound interpreter product. The durable signal in reported issues reflects memory-buffer handling challenges inherent to a native audio-processing codebase, with observed weaknesses clustering around improper restriction of operations within memory bounds. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Csounds over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-0270HIGH Multiple stack-based buffer overflows in Csound before 5.16.6 allow remote attackers to execute arbitrary code via a crafted (1) hetro file to the getnum function in util/heti_main | Feb 17, 2014 | 7.5 | 72 | NO | YES |
CVE-2012-2106HIGH Integer overflow in the pv_import function in util/pv_import.c in Csound 5.16.6, when converting a file, allows remote attackers to execute arbitrary code via a crafted file, which | Feb 4, 2014 | 9.3 | 30 | NO | NO |
CVE-2012-2108HIGH Stack-based buffer overflow in the main function in util/lpci_main.c in Csound before 5.17.2, when converting a file, allows user-assisted remote attackers to execute arbitrary cod | Feb 4, 2014 | 9.3 | 29 | NO | NO |
CVE-2012-2107HIGH Integer overflow in the main function in util/lpci_main.c in Csound before 5.17.2, when converting a file, allows user-assisted remote attackers to execute arbitrary code via a cra | Feb 4, 2014 | 9.3 | 29 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Csounds.
Media articles that mention a CVE ID that affects a product developed by Csounds — matched by CVE ID, not by vendor name.