Libopenmpt
Vendor:
First CVE: Jul 17, 2017 · Active for 9 years
11
Total CVEs
More Total CVEs than 89% of tracked products
3.7
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
7.4
Avg CVSS
Higher Avg CVSS than 49% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Libopenmpt over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 17, 2017
9 years ago
Most Recent CVE
Oct 4, 2019
2,485 days ago
CVE Severity & Scoring
Libopenmpt11 CVEs
55%
36%
9%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (9.1%)
Network10 (90.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None2 (18.2%)
Unknown0 (0.0%)
Required9 (81.8%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None11 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-17113CRITICAL In libopenmpt before 0.3.19 and 0.4.x before 0.4.9, ModPlug_InstrumentName and ModPlug_SampleName in libopenmpt_modplug.c do not restrict the lengths of libmodplug output-buffer st | Oct 4, 2019 | 9.8 | 30 | NO | NO |
CVE-2018-6611HIGH soundlib/Load_stp.cpp in OpenMPT through 1.27.04.00, and libopenmpt before 0.3.6, has an out-of-bounds read via a malformed STP file. | Feb 4, 2018 | 8.8 | 27 | NO | NO |
CVE-2018-11710HIGH soundlib/pattern.h in libopenmpt before 0.3.9 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted AMS f | Jun 4, 2018 | 8.8 | 26 | NO | NO |
CVE-2019-14382MEDIUM DSM in libopenmpt before 0.4.2 allows an assertion failure during file parsing with debug STLs. | Jul 30, 2019 | 6.5 | 22 | NO | NO |
CVE-2019-14380MEDIUM libopenmpt before 0.4.5 allows a crash during playback due to an out-of-bounds read in XM and MT2 files. | Jul 30, 2019 | 6.5 | 22 | NO | NO |
CVE-2019-14381HIGH libopenmpt before 0.4.3 allows a crash due to a NULL pointer dereference when doing a portamento from an OPL instrument to an empty instrument note map slot. | Jul 30, 2019 | 7.5 | 22 | NO | NO |
CVE-2018-10017MEDIUM soundlib/Snd_fx.cpp in OpenMPT before 1.27.07.00 and libopenmpt before 0.3.8 allows remote attackers to cause a denial of service (out-of-bounds read) via an IT or MO3 file with ma | Apr 11, 2018 | 6.5 | 22 | NO | NO |
CVE-2019-14383MEDIUM J2B in libopenmpt before 0.4.2 allows an assertion failure during file parsing with debug STLs. | Jul 30, 2019 | 6.5 | 21 | NO | NO |
CVE-2018-20860MEDIUM libopenmpt before 0.3.13 allows a crash with malformed MED files. | Jul 30, 2019 | 6.5 | 21 | NO | NO |
CVE-2018-20861MEDIUM libopenmpt before 0.3.11 allows a crash with certain malformed custom tunings in MPTM files. | Jul 30, 2019 | 6.5 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (11 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (11 CVEs).
Media Mentions
Signals from CVEs in this product scope (11 CVEs).
Top CNAs Publishing CVEs For Libopenmpt
Top CWEs
Versions
No cataloged versions.