Un4seen develops a focused suite of audio-playback and music-composition software including BASS, BASSMIDI, and XMPlay, which operate at the parser and codec level and handle untrusted media input. The vendor's vulnerability profile centers on memory-safety issues including infinite loops, out-of-bounds reads and writes, and use-after-free conditions that are characteristic of audio-decoding and format-parsing libraries. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Un4seen over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-6063HIGH Stack-based buffer overflow in Un4seen XMPlay 3.3.0.5 and earlier allows remote attackers to execute arbitrary code via a M3U file containing a long (1) FileName, and cause a crash | Nov 22, 2006 | 7.5 | 68 | NO | YES |
CVE-2019-19513CRITICAL The BASSMIDI plugin 2.4.12.1 for Un4seen BASS Audio Library on Windows is prone to an out of bounds write vulnerability. An attacker may exploit this to execute code on the target | Oct 16, 2020 | 9.8 | 33 | NO | NO |
CVE-2019-18796MEDIUM The BASS Audio Library 2.4.14 under Windows is prone to a BASS_StreamCreateFile Denial of Service vulnerability (infinite loop) via a crafted .mp3 file. This weakness could allow a | Oct 16, 2020 | 6.5 | 22 | NO | NO |
CVE-2019-18795MEDIUM The BASS Audio Library 2.4.14 under Windows is prone to a BASS_StreamCreateFile out of bounds read vulnerability via a crafted .wav file. An attacker can exploit this issues to gai | Oct 16, 2020 | 6.5 | 22 | NO | NO |
CVE-2019-18794MEDIUM The BASS Audio Library 2.4.14 under Windows is prone to a BASS_StreamCreateFile Use after Free vulnerability via a crafted .ogg file. An attacker can exploit this to gain access to | Oct 16, 2020 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Un4seen.
Media articles that mention a CVE ID that affects a product developed by Un4seen — matched by CVE ID, not by vendor name.