VYPR

Amarok

by KDE

CVEs (2)

  • CVE-2020-13152MedMay 20, 2020
    risk 0.39cvss 5.5epss 0.03

    A remote user can create a specially crafted M3U file, media playlist file that when loaded by the target user, will trigger a memory leak, whereby Amarok 2.8.0 continue to waste resources over time, eventually allows attackers to cause a denial of service.

  • CVE-2008-3699Aug 14, 2008
    risk 0.00cvss epss 0.00

    The MagnatuneBrowser::listDownloadComplete function in magnatunebrowser/magnatunebrowser.cpp in Amarok before 1.4.10 allows local users to overwrite arbitrary files via a symlink attack on the album_info.xml temporary file.