Owntone
Owntone Server: vulnerabilidades y CVE
Owntone Server tiene 7 vulnerabilidades publicadas, 6 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE7
Últimos 12 meses6
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-41458 | Alta (8.2) | 0.52% | — | 22 abr 2026 | OwnTone Server versions 28.4 through 29.0 contain a race condition vulnerability in the DAAP login handler that allows unauthenticated attackers to crash the server by exploiting unsynchronized access to the global DAAP… |
| CVE-2026-41457 | Media (6.9) | 0.43% | — | 22 abr 2026 | OwnTone Server versions 28.4 through 29.0 contain a SQL injection vulnerability in DAAP query and filter handling that allows attackers to inject arbitrary SQL expressions by supplying malicious values through the… |
| CVE-2025-63648 | Alta (7.5) | 0.38% | — | 20 ene 2026 | A NULL pointer dereference in the dacp_reply_playqueueedit_move function (src/httpd_dacp.c) of owntone-server commit b7e385f allows attackers to cause a Denial of Service (DoS) via sending a crafted DACP request to the… |
| CVE-2025-63647 | Alta (7.5) | 0.41% | — | 20 ene 2026 | A NULL pointer dereference in the parse_meta function (src/httpd_daap.c) of owntone-server commit 334beb allows attackers to cause a Denial of Service (DoS) via sending a crafted DAAP request to the server. |
| CVE-2025-57156 | Alta (7.5) | 0.50% | — | 20 ene 2026 | NULL pointer dereference in the dacp_reply_playqueueedit_clear function in src/httpd_dacp.c in owntone-server through commit 6d604a1 (newer commit after version 28.12) allows remote attackers to cause a Denial of… |
| CVE-2025-57155 | Alta (7.5) | 0.39% | — | 20 ene 2026 | NULL pointer dereference in the daap_reply_groups function in src/httpd_daap.c in owntone-server through commit 5e6f19a (newer commit after version 28.2) allows remote attackers to cause a Denial of Service. |
| CVE-2021-38383 | Crítica (9.8) | 1.2% | — | 10 ago 2021 | OwnTone (aka owntone-server) through 28.1 has a use-after-free in net_bind() in misc.c. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.