Schismtracker is a niche audio tracker and music composition application whose vulnerability profile centers on memory-safety issues, specifically out-of-bounds writes and integer underflow conditions that arise during audio file parsing and buffer manipulation. These weakness classes are characteristic of audio processing software handling untrusted input formats, and current severity and exploitation status are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Schismtracker over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-14465HIGH fmt_mtm_load_song in fmt/mtm.c in Schism Tracker 20190722 has a heap-based buffer overflow. | Jul 31, 2019 | 7.8 | 26 | NO | NO |
CVE-2019-14524HIGH An issue was discovered in Schism Tracker through 20190722. There is a heap-based buffer overflow via a large number of song patterns in fmt_mtm_load_song in fmt/mtm.c, a different | Aug 2, 2019 | 7.8 | 24 | NO | NO |
CVE-2019-14523HIGH An issue was discovered in Schism Tracker through 20190722. There is an integer underflow via a large plen in fmt_okt_load_song in the Amiga Oktalyzer parser in fmt/okt.c. | Aug 2, 2019 | 7.8 | 24 | NO | NO |
CVE-2021-32419MEDIUM An issue in Schism Tracker v20200412 fixed in v.20200412 allows attacker to obtain sensitive information via the fmt_mtm_load_song function in fmt/mtm.c. | Feb 17, 2023 | 5.3 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Schismtracker.
Media articles that mention a CVE ID that affects a product developed by Schismtracker — matched by CVE ID, not by vendor name.