Search CVE reports


Toggle filters

1 – 4 of 4 results


CVE-2024-44866

Medium priority
Needs evaluation

A buffer overflow in the GuitarPro1::read function of MuseScore Studio v4.3.2 allows attackers to to execute arbitrary code or cause a Denial of Service (DoS) via opening a crafted GuitarPro file.

3 affected packages

musescore, musescore2, musescore3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
musescore Not in release Not in release Needs evaluation Needs evaluation
musescore2 Needs evaluation Needs evaluation Not in release
musescore3 Needs evaluation Needs evaluation Not in release
Show less packages

CVE-2023-44428

Medium priority
Needs evaluation

MuseScore CAP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of MuseScore. User interaction is required...

3 affected packages

musescore, musescore2, musescore3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
musescore Not in release Not in release Needs evaluation Needs evaluation
musescore2 Needs evaluation Needs evaluation Not in release
musescore3 Needs evaluation Needs evaluation Not in release
Show less packages

CVE-2023-26923

Medium priority
Needs evaluation

Musescore 3.0 to 4.0.1 has a stack buffer overflow vulnerability that occurs when reading misconfigured midi files. If attacker can additional information, attacker can execute arbitrary code.

1 affected package

musescore

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
musescore Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2020-15999

High priority

Some fixes available 16 of 17

Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

18 affected packages

chromium-browser, godot, graphicsmagick, musescore, openjdk-13...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser Not affected Not affected Not in release Fixed
godot Not affected Not affected Not affected Not in release
graphicsmagick Not affected Not affected Not affected Not affected
musescore Not in release Not in release Not affected Not affected
openjdk-13 Not in release Not in release Not affected Not in release
texmaker Not affected Not affected Not affected Not affected
android Not in release Not in release Not in release Not in release
firefox Not affected Not affected Not in release Not affected
freetype Fixed Fixed Fixed Fixed
openjdk-lts Not affected Not affected Not affected Not affected
openjdk-15 Not in release Not in release Not in release Not in release
oxide-qt Not in release Not in release Not in release Not in release
paraview Not affected Not affected Not affected Not affected
qtbase-opensource-src Not affected Not affected Not affected Not affected
thunderbird Not affected Not affected Not in release Not affected
openjdk-12 Not in release Not in release Not in release Not in release
qtbase-opensource-src-gles Not affected Not affected Not affected Not in release
texlive-bin Not affected Not affected Not affected Not affected
Show all 18 packages Show less packages