Show filters
29 Total Results
Displaying 11-20 of 29
Sort by:
Attacker Value
Unknown

CVE-2019-10807

Disclosure Date: March 11, 2020 (last updated February 21, 2025)
Blamer versions prior to 1.0.1 allows execution of arbitrary commands. It is possible to inject arbitrary commands as part of the arguments provided to blamer.
Attacker Value
Unknown

CVE-2019-16309

Disclosure Date: September 14, 2019 (last updated November 27, 2024)
FlameCMS 3.3.5 has SQL injection in account/login.php via accountName.
Attacker Value
Unknown

CVE-2017-15046

Disclosure Date: October 06, 2017 (last updated November 26, 2024)
LAME 3.99.5, 3.99.4, 3.98.4, 3.98.2, 3.98 and 3.97 have a stack-based buffer overflow in unpack_read_samples in frontend/get_audio.c, a different vulnerability than CVE-2017-9412.
Attacker Value
Unknown

CVE-2017-15045

Disclosure Date: October 06, 2017 (last updated November 26, 2024)
LAME 3.99, 3.99.1, 3.99.2, 3.99.3, 3.99.4, 3.99.5, 3.98.4, 3.98.2 and 3.98 has a heap-based buffer over-read in fill_buffer in libmp3lame/util.c, related to lame_encode_buffer_sample_t in libmp3lame/lame.c, a different vulnerability than CVE-2017-9410.
0
Attacker Value
Unknown

CVE-2017-15018

Disclosure Date: October 05, 2017 (last updated November 26, 2024)
LAME 3.99.5, 3.99.4, 3.99.3, 3.99.2, 3.99.1, 3.99, 3.98.4, 3.98.2 and 3.98 have a heap-based buffer over-read when handling a malformed file in k_34_4 in vbrquantize.c.
Attacker Value
Unknown

CVE-2017-15019

Disclosure Date: October 05, 2017 (last updated November 26, 2024)
LAME 3.99.5 has a NULL Pointer Dereference in the hip_decode_init function within libmp3lame/mpglib_interface.c via a malformed mpg file, because of an incorrect calloc call.
0
Attacker Value
Unknown

CVE-2017-13712

Disclosure Date: August 28, 2017 (last updated November 26, 2024)
NULL Pointer Dereference in the id3v2AddAudioDuration function in libmp3lame/id3tag.c in LAME 3.99.5 allows attackers to perform Denial of Service by triggering a NULL first argument.
0
Attacker Value
Unknown

CVE-2017-11720

Disclosure Date: July 28, 2017 (last updated November 26, 2024)
There is a division-by-zero vulnerability in LAME 3.99.5, caused by a malformed input file.
0
Attacker Value
Unknown

CVE-2017-9412

Disclosure Date: July 27, 2017 (last updated November 26, 2024)
The unpack_read_samples function in frontend/get_audio.c in LAME 3.99.5 allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted wav file.
0
Attacker Value
Unknown

CVE-2015-9099

Disclosure Date: June 25, 2017 (last updated November 26, 2024)
The lame_init_params function in lame.c in libmp3lame.a in LAME 3.99.5 allows remote attackers to cause a denial of service (invalid read and application crash) via a crafted audio file with a negative sample rate.
0