Vulnerabilities > Lame Project
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2017-06-25 | CVE-2017-9869 | Out-of-bounds Read vulnerability in Lame Project Lame 3.99.5 The II_step_one function in layer2.c in mpglib, as used in libmpgdecoder.a in LAME 3.99.5 and other products, allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted audio file. | 4.3 |
2017-06-25 | CVE-2015-9101 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Lame Project Lame The fill_buffer_resample function in util.c in libmp3lame.a in LAME 3.98.4, 3.98.2, 3.98, 3.99, 3.99.1, 3.99.2, 3.99.3, 3.99.4 and 3.99.5 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted audio file. | 4.3 |
2017-06-25 | CVE-2015-9100 | NULL Pointer Dereference vulnerability in Lame Project Lame 3.99.5 The fill_buffer_resample function in util.c in libmp3lame.a in LAME 3.99.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted audio file. | 4.3 |
2017-06-25 | CVE-2015-9099 | Out-of-bounds Read vulnerability in Lame Project Lame 3.99.5 The lame_init_params function in lame.c in libmp3lame.a in LAME 3.99.5 allows remote attackers to cause a denial of service (invalid read and application crash) via a crafted audio file with a negative sample rate. | 4.3 |
2017-05-02 | CVE-2017-8419 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Lame Project Lame 3.99.5 LAME through 3.99.5 relies on the signed integer data type for values in a WAV or AIFF header, which allows remote attackers to cause a denial of service (stack-based buffer overflow or heap-based buffer overflow) or possibly have unspecified other impact via a crafted file, as demonstrated by mishandling of num_channels. | 6.8 |