Search CVE reports


Toggle filters

11 – 18 of 18 results


CVE-2017-9871

Low priority
Vulnerable

The III_i_stereo function in layer3.c in mpglib, as used in libmpgdecoder.a in LAME 3.99.5 and other products, allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) or possibly...

1 affected package

lame

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
lame Not affected Not affected Not affected Not affected
Show less packages

CVE-2017-9870

Low priority
Vulnerable

The III_i_stereo function in layer3.c in mpglib, as used in libmpgdecoder.a in LAME 3.99.5 and other products, allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted audio file...

1 affected package

lame

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
lame Not affected Not affected Not affected Not affected
Show less packages

CVE-2017-9869

Negligible priority
Vulnerable

The II_step_one function in layer2.c in mpglib, as used in libmpgdecoder.a in LAME 3.99.5 and other products, allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted audio file.

1 affected package

lame

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
lame Not affected Not affected Not affected Not affected
Show less packages

CVE-2015-9101

Medium priority
Fixed

The fill_buffer_resample function in util.c in libmp3lame.a in LAME 3.98.4, 3.98.2, 3.98, 3.99, 3.99.1, 3.99.2, 3.99.3, 3.99.4 and 3.99.5 allows remote attackers to cause a denial of service (heap-based buffer over-read...

1 affected package

lame

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
lame Not affected Not affected Not affected
Show less packages

CVE-2015-9100

Medium priority
Fixed

The fill_buffer_resample function in util.c in libmp3lame.a in LAME 3.99.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted audio file.

1 affected package

lame

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
lame Not affected Not affected Not affected
Show less packages

CVE-2015-9099

Medium priority
Fixed

The lame_init_params function in lame.c in libmp3lame.a in LAME 3.99.5 allows remote attackers to cause a denial of service (invalid read and application crash) via a crafted audio file with a negative sample rate.

1 affected package

lame

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
lame Not affected Not affected Not affected
Show less packages

CVE-2017-8419

Medium priority

Some fixes available 1 of 4

LAME through 3.99.5 relies on the signed integer data type for values in a WAV or AIFF header, which allows remote attackers to cause a denial of service (stack-based buffer overflow or heap-based buffer overflow) or possibly have...

1 affected package

lame

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
lame Not affected Not affected Not affected
Show less packages

CVE-2008-5141

Low priority

Some fixes available 2 of 4

flamethrower in flamethrower 0.1.8 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/multicast.tar.##### temporary file.

1 affected package

flamethrower

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
flamethrower
Show less packages