Konstanty Bialkowski
Konstanty Bialkowski Libmodplug: vulnerabilities and CVEs
Konstanty Bialkowski Libmodplug has 12 published vulnerabilities, 1 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.
CVEs12
Last 12 months1
Critical0
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-75904 | Medium (4.8) | 0.17% | — | Aug 18, 2026 | libmodplug through 0.8.9.1 contains an out-of-bounds read in pat_smplooped in src/load_pat.cpp. The function validates only the upper bound of its sample index against MAXSMP and then subtracts one before indexing the… |
| CVE-2013-4234 | Medium (6.8) | 4.4% | — | Sep 16, 2013 | Multiple heap-based buffer overflows in the (1) abc_MIDI_drum and (2) abc_MIDI_gchord functions in load_abc.cpp in libmodplug 0.8.8.4 and earlier allow remote attackers to cause a denial of service (memory corruption… |
| CVE-2013-4233 | Medium (6.8) | 4.1% | — | Sep 16, 2013 | Integer overflow in the abc_set_parts function in load_abc.cpp in libmodplug 0.8.8.4 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted P header in an ABC… |
| CVE-2011-2915 | Medium (6.8) | 4.2% | — | Jun 7, 2012 | Off-by-one error in the CSoundFile::ReadAMS2 function in src/load_ams.cpp in libmodplug before 0.8.8.4 allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via a… |
| CVE-2011-2914 | Medium (6.8) | 4.6% | — | Jun 7, 2012 | Off-by-one error in the CSoundFile::ReadDSM function in src/load_dms.cpp in libmodplug before 0.8.8.4 allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via a… |
| CVE-2011-2913 | Medium (6.8) | 4.6% | — | Jun 7, 2012 | Off-by-one error in the CSoundFile::ReadAMS function in src/load_ams.cpp in libmodplug before 0.8.8.4 allows remote attackers to cause a denial of service (stack memory corruption) and possibly execute arbitrary code… |
| CVE-2011-2912 | Medium (6.8) | 4.3% | — | Jun 7, 2012 | Stack-based buffer overflow in the CSoundFile::ReadS3M function in src/load_s3m.cpp in libmodplug before 0.8.8.4 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted S3M… |
| CVE-2011-2911 | Medium (6.8) | 4.3% | — | Jun 7, 2012 | Integer overflow in the CSoundFile::ReadWav function in src/load_wav.cpp in libmodplug before 0.8.8.4 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted WAV file,… |
| CVE-2011-1761 | Medium (6.8) | 11% | — | Jun 7, 2012 | Multiple stack-based buffer overflows in the (1) abc_new_macro and (2) abc_new_umacro functions in src/load_abc.cpp in libmodplug before 0.8.8.3 allow remote attackers to cause a denial of service (crash) and possibly… |
| CVE-2011-1574 | Medium (6.8) | 43% | — | May 9, 2011 | Stack-based buffer overflow in the ReadS3M method in load_s3m.cpp in libmodplug before 0.8.8.2 allows remote attackers to execute arbitrary code via a crafted S3M file. |
| CVE-2009-1513 | Medium (6.8) | 4.1% | — | May 4, 2009 | Buffer overflow in the PATinst function in src/load_pat.cpp in libmodplug before 0.8.7 allows user-assisted remote attackers to cause a denial of service and possibly execute arbitrary code via a long instrument name. |
| CVE-2009-1438 | High (7.5) | 4.7% | — | Apr 27, 2009 | Integer overflow in the CSoundFile::ReadMed function (src/load_med.cpp) in libmodplug before 0.8.6, as used in gstreamer-plugins, TTPlayer, and other products, allows context-dependent attackers to execute arbitrary… |