Vulnerabilities > Openmpt > Libopenmpt > 0.3.11

DATE CVE VULNERABILITY TITLE RISK
2019-10-04 CVE-2019-17113 Classic Buffer Overflow vulnerability in Openmpt Libopenmpt
In libopenmpt before 0.3.19 and 0.4.x before 0.4.9, ModPlug_InstrumentName and ModPlug_SampleName in libopenmpt_modplug.c do not restrict the lengths of libmodplug output-buffer strings in the C API, leading to a buffer overflow.
network
low complexity
openmpt CWE-120
7.5
2019-07-30 CVE-2019-14383 Reachable Assertion vulnerability in multiple products
J2B in libopenmpt before 0.4.2 allows an assertion failure during file parsing with debug STLs.
network
low complexity
openmpt opensuse CWE-617
6.5
2019-07-30 CVE-2019-14382 Reachable Assertion vulnerability in Openmpt Libopenmpt
DSM in libopenmpt before 0.4.2 allows an assertion failure during file parsing with debug STLs.
network
low complexity
openmpt CWE-617
6.5
2019-07-30 CVE-2019-14380 Out-of-bounds Read vulnerability in multiple products
libopenmpt before 0.4.5 allows a crash during playback due to an out-of-bounds read in XM and MT2 files.
network
low complexity
openmpt debian CWE-125
6.5
2019-07-30 CVE-2018-20860 Improper Input Validation vulnerability in multiple products
libopenmpt before 0.3.13 allows a crash with malformed MED files.
network
low complexity
openmpt opensuse CWE-20
6.5
2019-07-30 CVE-2019-14381 NULL Pointer Dereference vulnerability in Openmpt Libopenmpt
libopenmpt before 0.4.3 allows a crash due to a NULL pointer dereference when doing a portamento from an OPL instrument to an empty instrument note map slot.
network
low complexity
openmpt CWE-476
5.0