MuseScore is a music notation and composition application with a narrowly scoped product footprint. Its observed vulnerability surface centers on memory-safety issues including out-of-bounds writes and heap-based buffer overflows, typical of applications that parse and manipulate complex file formats. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Musescore over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-44428HIGH MuseScore CAP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installa | May 3, 2024 | 7.8 | 24 | NO | NO |
CVE-2023-26923HIGH Musescore 3.0 to 4.0.1 has a stack buffer overflow vulnerability that occurs when reading misconfigured midi files. If attacker can additional information, attacker can execute arb | Mar 28, 2023 | 7.0 | 23 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Musescore.
Media articles that mention a CVE ID that affects a product developed by Musescore — matched by CVE ID, not by vendor name.