VYPR

Stepmania

by stepmania

Source repositories

CVEs (2)

  • CVE-2020-20412MedDec 26, 2020
    risk 0.42cvss 6.5epss 0.01

    lib/codebook.c in libvorbis before 1.3.6, as used in StepMania 5.0.12 and other products, has insufficient array bounds checking via a crafted OGG file. NOTE: this may overlap CVE-2018-5146.

  • CVE-2022-25010CriMar 1, 2022
    risk 0.00cvss 9.1epss 0.01

    The component /rootfs in RageFile of Stepmania v5.1b2 and below allows attackers access to the entire file system.