Openmpt is a modular music tracker and audio-library project with a compact product footprint centered on libopenmpt and the tracker application itself, which despite narrow scope sits prominently within digital-audio and retro-music communities. Its vulnerability signal clusters around memory-safety and input-handling weaknesses—out-of-bounds reads, buffer overflows, improper input validation, and reachable assertions—that are characteristic of audio-format parsers processing untrusted file input, and a meaningful share of disclosures reach serious severity. Defenders working with music-production tools or embedded audio libraries should monitor this vendor's releases for format-parsing updates; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Openmpt over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-17113CRITICAL In libopenmpt before 0.3.19 and 0.4.x before 0.4.9, ModPlug_InstrumentName and ModPlug_SampleName in libopenmpt_modplug.c do not restrict the lengths of libmodplug output-buffer st | Oct 4, 2019 | 9.8 | 30 | NO | NO |
CVE-2018-6611HIGH soundlib/Load_stp.cpp in OpenMPT through 1.27.04.00, and libopenmpt before 0.3.6, has an out-of-bounds read via a malformed STP file. | Feb 4, 2018 | 8.8 | 27 | NO | NO |
CVE-2018-11710HIGH soundlib/pattern.h in libopenmpt before 0.3.9 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted AMS f | Jun 4, 2018 | 8.8 | 26 | NO | NO |
CVE-2019-14382MEDIUM DSM in libopenmpt before 0.4.2 allows an assertion failure during file parsing with debug STLs. | Jul 30, 2019 | 6.5 | 22 | NO | NO |
CVE-2019-14380MEDIUM libopenmpt before 0.4.5 allows a crash during playback due to an out-of-bounds read in XM and MT2 files. | Jul 30, 2019 | 6.5 | 22 | NO | NO |
CVE-2019-14381HIGH libopenmpt before 0.4.3 allows a crash due to a NULL pointer dereference when doing a portamento from an OPL instrument to an empty instrument note map slot. | Jul 30, 2019 | 7.5 | 22 | NO | NO |
CVE-2018-10017MEDIUM soundlib/Snd_fx.cpp in OpenMPT before 1.27.07.00 and libopenmpt before 0.3.8 allows remote attackers to cause a denial of service (out-of-bounds read) via an IT or MO3 file with ma | Apr 11, 2018 | 6.5 | 22 | NO | NO |
CVE-2019-14383MEDIUM J2B in libopenmpt before 0.4.2 allows an assertion failure during file parsing with debug STLs. | Jul 30, 2019 | 6.5 | 21 | NO | NO |
CVE-2018-20860MEDIUM libopenmpt before 0.3.13 allows a crash with malformed MED files. | Jul 30, 2019 | 6.5 | 21 | NO | NO |
CVE-2018-20861MEDIUM libopenmpt before 0.3.11 allows a crash with certain malformed custom tunings in MPTM files. | Jul 30, 2019 | 6.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Openmpt.
Media articles that mention a CVE ID that affects a product developed by Openmpt — matched by CVE ID, not by vendor name.