Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3037▲ 502 respecto a la semana anterior
Críticas / altas1448▲ 249 respecto a la semana anterior
Nueva explotación activa (KEV)8▼ 2 respecto a la semana anterior
Sin puntuar (sin CVSS)365▲ 158 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.8) | 0.17% | — | Konstanty Bialkowski LibmodplugAI | 18/8/2026 | 8/9/2026 | libmodplug through 0.8.9.1 contains an out-of-bounds read in pat_smplooped in src/load_pat.cpp. The function validates only the upper bound of its sample index against MAXSMP and then subtracts one before indexing the 191-byte static array pat_loops, so an index of zero reads pat_loops[-1], one byte before the array.… | |
| Modificada | Media (6.8) | 4.4% | — | Konstanty Bialkowski LibmodplugDebian Linux | 16/9/2013 | 16/6/2026 | Multiple heap-based buffer overflows in the (1) abc_MIDI_drum and (2) abc_MIDI_gchord functions in load_abc.cpp in libmodplug 0.8.8.4 and earlier allow remote attackers to cause a denial of service (memory corruption and crash) and possibly execute arbitrary code via a crafted ABC. | |
| Modificada | Media (6.8) | 4.1% | — | Konstanty Bialkowski LibmodplugDebian Linux | 16/9/2013 | 16/6/2026 | Integer overflow in the abc_set_parts function in load_abc.cpp in libmodplug 0.8.8.4 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted P header in an ABC file, which triggers a heap-based buffer overflow. | |
| Modificada | Media (6.8) | 4.2% | — | Konstanty Bialkowski Libmodplug | 7/6/2012 | 16/6/2026 | Off-by-one error in the CSoundFile::ReadAMS2 function in src/load_ams.cpp in libmodplug before 0.8.8.4 allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via a crafted AMS file with a large number of instruments. | |
| Modificada | Media (6.8) | 4.6% | — | Konstanty Bialkowski Libmodplug | 7/6/2012 | 16/6/2026 | Off-by-one error in the CSoundFile::ReadDSM function in src/load_dms.cpp in libmodplug before 0.8.8.4 allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via a crafted DSM file with a large number of samples. | |
| Modificada | Media (6.8) | 4.6% | — | Konstanty Bialkowski Libmodplug | 7/6/2012 | 16/6/2026 | Off-by-one error in the CSoundFile::ReadAMS function in src/load_ams.cpp in libmodplug before 0.8.8.4 allows remote attackers to cause a denial of service (stack memory corruption) and possibly execute arbitrary code via a crafted AMS file with a large number of samples. | |
| Modificada | Media (6.8) | 4.3% | — | Konstanty Bialkowski Libmodplug | 7/6/2012 | 16/6/2026 | Stack-based buffer overflow in the CSoundFile::ReadS3M function in src/load_s3m.cpp in libmodplug before 0.8.8.4 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted S3M file with an invalid offset. | |
| Modificada | Media (6.8) | 4.3% | — | Konstanty Bialkowski Libmodplug | 7/6/2012 | 16/6/2026 | Integer overflow in the CSoundFile::ReadWav function in src/load_wav.cpp in libmodplug before 0.8.8.4 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted WAV file, which triggers a heap-based buffer overflow. | |
| Modificada | Media (6.8) | 11% | — | Konstanty Bialkowski Libmodplug | 7/6/2012 | 16/6/2026 | Multiple stack-based buffer overflows in the (1) abc_new_macro and (2) abc_new_umacro functions in src/load_abc.cpp in libmodplug before 0.8.8.3 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted ABC file. NOTE: some of these details are obtained from third… | |
| Modificada | Media (6.8) | 43% | — | Konstanty Bialkowski Libmodplug | 9/5/2011 | 16/6/2026 | Stack-based buffer overflow in the ReadS3M method in load_s3m.cpp in libmodplug before 0.8.8.2 allows remote attackers to execute arbitrary code via a crafted S3M file. | |
| Modificada | Media (6.8) | 4.1% | — | Konstanty Bialkowski Libmodplug | 4/5/2009 | 16/6/2026 | Buffer overflow in the PATinst function in src/load_pat.cpp in libmodplug before 0.8.7 allows user-assisted remote attackers to cause a denial of service and possibly execute arbitrary code via a long instrument name. | |
| Modificada | Alta (7.5) | 4.7% | — | Konstanty Bialkowski Libmodplug | 27/4/2009 | 16/6/2026 | Integer overflow in the CSoundFile::ReadMed function (src/load_med.cpp) in libmodplug before 0.8.6, as used in gstreamer-plugins, TTPlayer, and other products, allows context-dependent attackers to execute arbitrary code via a MED file with a crafted (1) song comment or (2) song name, which triggers a heap-based… |