Linuxsampler is an audio synthesis framework whose vulnerability footprint centers on its core library component, libgig, which handles parsed audio and instrument data. The recurring weakness classes—out-of-bounds reads and writes, buffer-boundary violations, NULL-pointer dereferences, and divide-by-zero conditions—reflect the memory-unsafe parsing and arithmetic operations inherent to audio codec and format handling, and a meaningful share of the vendor's disclosures reach serious severity. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Linuxsampler over time
Signals from CVEs in this vendor scope (19 CVEs).
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-12950MEDIUM The gig::Region::Region function in gig.cpp in libgig 4.0.0 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted gig | Aug 28, 2017 | 6.5 | 32 | NO | YES |
CVE-2018-18197CRITICAL An issue was discovered in libgig 4.1.0. There is an operator new[] failure (due to a big pSampleLoops heap request) in DLS::Sampler::Sampler in DLS.cpp. | Oct 9, 2018 | 9.8 | 30 | NO | NO |
CVE-2018-18196HIGH An issue was discovered in libgig 4.1.0. There is a heap-based buffer over-read in RIFF::List::GetListTypeString in RIFF.cpp. | Oct 9, 2018 | 8.8 | 27 | NO | NO |
CVE-2018-18194HIGH An issue was discovered in libgig 4.1.0. There is a heap-based buffer over-read in DLS::Region::GetSample() in DLS.cpp. | Oct 9, 2018 | 8.8 | 27 | NO | NO |
CVE-2018-18193HIGH An issue was discovered in libgig 4.1.0. There is operator new[] failure (due to a big pWavePoolTable heap request) in DLS::File::File in DLS.cpp. | Oct 9, 2018 | 8.8 | 27 | NO | NO |
CVE-2018-14455HIGH An issue was discovered in libgig 4.1.0. There is an out-of-bounds write in pData[0] access in the function store32 in helper.h. | Jul 20, 2018 | 8.8 | 26 | NO | NO |
CVE-2018-14453HIGH An issue was discovered in libgig 4.1.0. There is a heap-based buffer overflow in pData[1] access in the function store16 in helper.h. | Jul 20, 2018 | 8.8 | 26 | NO | NO |
CVE-2018-14452HIGH An issue was discovered in libgig 4.1.0. There is an out-of-bounds read in the "always assign the sample of the first dimension region of this region" feature of the function gig:: | Jul 20, 2018 | 8.8 | 26 | NO | NO |
CVE-2021-32294HIGH An issue was discovered in libgig through 20200507. A heap-buffer-overflow exists in the function RIFF::List::GetSubList located in RIFF.cpp. It allows an attacker to cause code Ex | Sep 20, 2021 | 8.8 | 25 | NO | NO |
CVE-2018-14459HIGH An issue was discovered in libgig 4.1.0. There is an out-of-bounds write in pData[0] access in the function store16 in helper.h. | Jul 20, 2018 | 8.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (19 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Linuxsampler.
Media articles that mention a CVE ID that affects a product developed by Linuxsampler — matched by CVE ID, not by vendor name.