Wine is a translation layer that enables Windows applications to run on Unix-like systems, representing a narrow but structurally important compatibility bridge in cross-platform software deployments. The observed vulnerability profile centers on out-of-bounds write conditions within the Wine codebase itself, reflecting the memory-management complexity inherent to a large C-based compatibility implementation. Current vulnerability counts, severity assessments, and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Winehq over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-12933CRITICAL PlayEnhMetaFileRecord in enhmetafile.c in Wine 3.7 allows attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact because the attacke | Jun 28, 2018 | 9.8 | 31 | NO | NO |
CVE-2018-12932CRITICAL PlayEnhMetaFileRecord in enhmetafile.c in Wine 3.7 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact by triggerin | Jun 28, 2018 | 9.8 | 31 | NO | NO |
CVE-2026-48831HIGH Wine ships a .desktop file that registers itself as a MIME handler for EXE files and several other Windows executable file types. In some configurations, handling of an EXE file ca | May 24, 2026 | 7.3 | 30 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Winehq.
Media articles that mention a CVE ID that affects a product developed by Winehq — matched by CVE ID, not by vendor name.