Mindwerks develops WildMIDI, a MIDI music-file parser and playback library embedded across audio applications and media players, with observed vulnerabilities centered on memory-access safety in the parsing layer. The recurring weakness classes—out-of-bounds reads and improper buffer-boundary enforcement—reflect the hazards of parsing untrusted audio input in a native codebase where remediation depends on downstream integrators rebuilding their products. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mindwerks over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-11662HIGH The _WM_ParseNewMidi function in f_midi.c in WildMIDI 0.4.2 can cause a denial of service (invalid memory read and application crash) via a crafted mid file. | Aug 17, 2017 | 7.5 | 37 | NO | YES |
CVE-2017-11661HIGH The _WM_SetupMidiEvent function in internal_midi.c:2318 in WildMIDI 0.4.2 can cause a denial of service (invalid memory read and application crash) via a crafted mid file. | Aug 17, 2017 | 7.5 | 33 | NO | YES |
CVE-2017-11663MEDIUM The _WM_SetupMidiEvent function in internal_midi.c:2315 in WildMIDI 0.4.2 can cause a denial of service (invalid memory read and application crash) via a crafted mid file. | Aug 17, 2017 | 6.5 | 32 | NO | YES |
CVE-2017-11664MEDIUM The _WM_SetupMidiEvent function in internal_midi.c:2122 in WildMIDI 0.4.2 can cause a denial of service (invalid memory read and application crash) via a crafted mid file. | Aug 17, 2017 | 6.5 | 29 | NO | YES |
CVE-2017-1000418HIGH The WildMidi_Open function in WildMIDI since commit d8a466829c67cacbb1700beded25c448d99514e5 allows remote attackers to cause a denial of service (heap-based buffer overflow and ap | Jan 2, 2018 | 7.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mindwerks.
Media articles that mention a CVE ID that affects a product developed by Mindwerks — matched by CVE ID, not by vendor name.