CVE-2026-58264
- EPSS 0.59%
- Veröffentlicht 18.09.2026 20:17:18
- Zuletzt bearbeitet 24.09.2026 21:25:27
FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 1.1.2 until 2.5.6, the FluidSynth command handler accepts a pitch_bend_range command whose channel argument is not bounds checked before the supplied value is written ...
CVE-2026-61714
- EPSS 0.14%
- Veröffentlicht 18.09.2026 20:17:18
- Zuletzt bearbeitet 25.09.2026 17:17:09
FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.2.4 until 2.5.6, configuring synth.midi-channels above 16 allows the MIDI player to index _fluid_player_t::channel_isplaying outside its fixed-size heap allocation w...
CVE-2026-61720
- EPSS 0.14%
- Veröffentlicht 18.09.2026 20:17:18
- Zuletzt bearbeitet 24.09.2026 21:25:27
FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6, the SF2 parser computes the DMOD modulator count as chunk.size / SF_MOD_SIZE - 1 without rejecting chunks smaller than one record. A crafted SF2 fil...
- EPSS 0.15%
- Veröffentlicht 18.09.2026 20:17:18
- Zuletzt bearbeitet 23.09.2026 18:12:04
FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6, the native DLS loader assigns file-controlled wsmp.loop_start and wsmp.loop_length values to samples without calling fluid_sample_validate() or flui...
CVE-2026-61722
- EPSS 0.15%
- Veröffentlicht 18.09.2026 20:17:18
- Zuletzt bearbeitet 23.09.2026 18:28:25
FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6, the native DLS parser validates articulation chunks using the unsigned expression cbsize + connblocks * 12 without first ensuring that the multiplic...
CVE-2026-61723
- EPSS 0.14%
- Veröffentlicht 18.09.2026 20:17:18
- Zuletzt bearbeitet 24.09.2026 21:25:27
FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6, the native DLS parser validates ptbl chunks with the unsigned expression cues * 4 + cbsize without checking whether the multiplication and addition ...
CVE-2025-56225
- EPSS 0.43%
- Veröffentlicht 09.01.2026 16:16:06
- Zuletzt bearbeitet 23.01.2026 02:13:04
fluidsynth-2.4.6 and earlier versions is vulnerable to Null pointer dereference in fluid_synth_monopoly.c, that can be triggered when loading an invalid midi file.
- EPSS 0.21%
- Veröffentlicht 23.12.2025 22:41:28
- Zuletzt bearbeitet 15.01.2026 02:01:38
FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From versions 2.5.0 to before 2.5.2, a race condition during unloading of a DLS file can trigger a heap-based use-after-free. A concurrently running thread may be pending t...
CVE-2021-21417
- EPSS 0.94%
- Veröffentlicht 29.04.2021 17:15:09
- Zuletzt bearbeitet 21.11.2024 05:48:19
fluidsynth is a software synthesizer based on the SoundFont 2 specifications. A use after free violation was discovered in fluidsynth, that can be triggered when loading an invalid SoundFont file.