Stepmania is a niche open-source rhythm game engine and related tools with a focused product footprint that has attracted modest vulnerability research attention. Its observed weaknesses center on array-index validation and permission-assignment issues, typical of applications handling user input and local resource access. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Stepmania over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-25010CRITICAL The component /rootfs in RageFile of Stepmania v5.1b2 and below allows attackers access to the entire file system. | Mar 1, 2022 | 9.1 | 29 | NO | NO |
CVE-2020-20412MEDIUM lib/codebook.c in libvorbis before 1.3.6, as used in StepMania 5.0.12 and other products, has insufficient array bounds checking via a crafted OGG file. NOTE: this may overlap CVE- | Dec 26, 2020 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Stepmania.
Media articles that mention a CVE ID that affects a product developed by Stepmania — matched by CVE ID, not by vendor name.