Vulnerabilities (CVE)

Filtered by vendor Fluidsynth Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-21417 2 Debian, Fluidsynth 2 Debian Linux, Fluidsynth 2021-09-14 4.3 MEDIUM 5.5 MEDIUM
fluidsynth is a software synthesizer based on the SoundFont 2 specifications. A use after free violation was discovered in fluidsynth, that can be triggered when loading an invalid SoundFont file.
CVE-2021-28421 1 Fluidsynth 1 Fluidsynth 2021-06-30 7.5 HIGH 9.8 CRITICAL
FluidSynth 2.1.7 contains a use after free vulnerability in sfloader/fluid_sffile.c that can result in arbitrary code execution or a denial of service (DoS) if a malicious soundfont2 file is loaded into a fluidsynth library.