VYPR

Csound

by Csound

CVEs (5)

  • CVE-2012-0270Feb 17, 2014
    risk 0.09cvss epss 0.75

    Multiple stack-based buffer overflows in Csound before 5.16.6 allow remote attackers to execute arbitrary code via a crafted (1) hetro file to the getnum function in util/heti_main.c or (2) PVOC file to the getnum function in util/pv_import.c.

  • CVE-2012-2108Feb 4, 2014
    risk 0.00cvss epss 0.06

    Stack-based buffer overflow in the main function in util/lpci_main.c in Csound before 5.17.2, when converting a file, allows user-assisted remote attackers to execute arbitrary code via a crafted file.

  • CVE-2012-2107Feb 4, 2014
    risk 0.00cvss epss 0.05

    Integer overflow in the main function in util/lpci_main.c in Csound before 5.17.2, when converting a file, allows user-assisted remote attackers to execute arbitrary code via a crafted file, which triggers a heap-based buffer overflow.

  • CVE-2012-2106Feb 4, 2014
    risk 0.00cvss epss 0.05

    Integer overflow in the pv_import function in util/pv_import.c in Csound 5.16.6, when converting a file, allows remote attackers to execute arbitrary code via a crafted file, which triggers a heap-based buffer overflow.

  • CVE-2008-5986Jan 28, 2009
    risk 0.00cvss epss 0.00

    Untrusted search path vulnerability in the (1) "VST plugin with Python scripting" and (2) "VST plugin for writing score generators in Python" in Csound 5.08.2, and possibly other versions, allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-5983).