All CVEs — page 102 of 242
The complete archive, 25 per page, newest first. 6034 records. Search instead.
The flaw is an integer overflow vulnerability in the mp3dec_skip_id3v1() function when parsing the APEv2 tag-size field, which can lead to arbitrary code execution. This matters because attackers can exploit it to execute malicious code, leading to severe system compromise.