Show filters
31 Total Results
Displaying 1-10 of 31
Sort by:
Attacker Value
Unknown
CVE-2024-7193
Disclosure Date: July 29, 2024 (last updated November 21, 2024)
A vulnerability has been found in Mp3tag up to 3.26d and classified as problematic. This vulnerability affects unknown code in the library tak_deco_lib.dll of the component DLL Handler. The manipulation leads to uncontrolled search path. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. Upgrading to version 3.26e is able to address this issue. It is recommended to upgrade the affected component. VDB-272614 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early, responded in a very professional manner and immediately released a fixed version of the affected product.
0
Attacker Value
Unknown
CVE-2023-0069
Disclosure Date: March 06, 2023 (last updated October 08, 2023)
The WPaudio MP3 Player WordPress plugin through 4.0.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
0
Attacker Value
Unknown
CVE-2022-36373
Disclosure Date: September 01, 2022 (last updated February 24, 2025)
Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Simon Ward MP3 jPlayer plugin <= 2.7.3 at WordPress.
0
Attacker Value
Unknown
CVE-2018-14002
Disclosure Date: July 12, 2018 (last updated November 08, 2023)
An integer overflow vulnerability exists in the function distribute of MP3 Coin (MP3), an Ethereum token smart contract. An attacker could use it to set any user's balance.
0
Attacker Value
Unknown
CVE-2018-10777
Disclosure Date: May 07, 2018 (last updated November 26, 2024)
Buffer overflow in the WriteMP3GainAPETag function in apetag.c in mp3gain through 1.5.2-r2 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.
0
Attacker Value
Unknown
CVE-2018-10778
Disclosure Date: May 07, 2018 (last updated November 26, 2024)
Read access violation in the III_dequantize_sample function in mpglibDBL/layer3.c in mp3gain through 1.5.2-r2 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact, a different vulnerability than CVE-2017-9872 and CVE-2017-14409.
0
Attacker Value
Unknown
CVE-2018-10776
Disclosure Date: May 07, 2018 (last updated November 26, 2024)
The getbits function in mpglibDBL/common.c in mp3gain through 1.5.2-r2 allows remote attackers to cause a denial of service (segmentation fault and application crash) or possibly have unspecified other impact.
0
Attacker Value
Unknown
CVE-2017-15221
Disclosure Date: October 16, 2017 (last updated November 26, 2024)
ASX to MP3 converter 3.1.3.7.2010.11.05 has a buffer overflow via a crafted M3U file, a related issue to CVE-2009-1324.
0
Attacker Value
Unknown
CVE-2017-15185
Disclosure Date: October 09, 2017 (last updated November 26, 2024)
plugins/ogg.c in Libmp3splt 0.9.2 calls the libvorbis vorbis_block_clear function with uninitialized data upon detection of invalid input, which allows remote attackers to cause a denial of service (application crash) via a crafted file.
0
Attacker Value
Unknown
CVE-2017-14406
Disclosure Date: September 13, 2017 (last updated November 26, 2024)
A NULL pointer dereference was discovered in sync_buffer in interface.c in mpglibDBL, as used in MP3Gain version 1.5.2. The vulnerability causes a segmentation fault and application crash, which leads to remote denial of service.
0