VYPR

TuxGuitar

by Tuxguitar

CVEs (2)

  • CVE-2020-14940HigJun 23, 2020
    risk 0.49cvss 7.5epss 0.04

    An issue was discovered in io/gpx/GPXDocumentReader.java in TuxGuitar 1.5.4. It uses misconfigured XML parsers, leading to XXE while loading GP6 (.gpx) and GP7 (.gp) tablature files.

  • CVE-2010-3385Oct 20, 2010
    risk 0.00cvss epss 0.00

    TuxGuitar 1.2 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.