wildmidi: Heap-based Buffer Overflow in WildMidi_Open
Published Jan 2, 2018
7.8
HIGHCVSS 3.0
EPSS 1.67%
Description
The WildMidi_Open function in WildMIDI since commit d8a466829c67cacbb1700beded25c448d99514e5 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted file.
Affected products
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
1 other source (Red Hat) ▾
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
AV:N/AC:M/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Table of values (14 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 1.67% (0.01672) | 75.95th | v5 (v2026.06.15) |
| Aug 23, 2026 | 2.52% (0.02516) | 83.50th | v5 (v2026.06.15) |
| Jul 20, 2024 | 0.09% (0.00091) | 39.56th | v3 (v2023.03.01) |
| Apr 25, 2024 | 0.09% (0.00091) | 38.35th | v3 (v2023.03.01) |
| Mar 15, 2024 | 0.08% (0.00081) | 33.19th | v3 (v2023.03.01) |
| Feb 8, 2024 | 0.07% (0.00074) | 29.93th | v3 (v2023.03.01) |
| Jan 18, 2024 | 0.23% (0.00228) | 61.11th | v3 (v2023.03.01) |
| Dec 13, 2023 | 0.19% (0.00190) | 56.46th | v3 (v2023.03.01) |
| Nov 12, 2023 | 0.16% (0.00161) | 52.62th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.13% (0.00134) | 46.71th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.05% (0.01055) | 52.13th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.05% (0.01055) | 27.52th | v2 (v2022.01.01) |
| Feb 3, 2022 | 0.98% (0.00976) | 26.54th | v5 (v2026.06.15) |
| Apr 14, 2021 | 0.98% (0.00976) | 0.00th | v1 |
References (6)
- https://access.redhat.com/security/cve/CVE-2017-1000418 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1532322 Issue Tracking
- https://github.com/Mindwerks/wildmidi/commit/814f31d8eceda8401eb812fc2e94ed143fdad0ab x_refsource_CONFIRMPatchThird Party Advisory
- https://github.com/Mindwerks/wildmidi/issues/178 x_refsource_CONFIRMExploitThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2017-1000418
- https://www.cve.org/CVERecord?id=CVE-2017-1000418
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2017-1000418 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1532322 | Issue Tracking | |
| https://github.com/Mindwerks/wildmidi/commit/814f31d8eceda8401eb812fc2e94ed143fdad0ab | x_refsource_CONFIRMPatchThird Party Advisory | |
| https://github.com/Mindwerks/wildmidi/issues/178 | x_refsource_CONFIRMExploitThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2017-1000418 | ||
| https://www.cve.org/CVERecord?id=CVE-2017-1000418 |
Change history (0)
No recorded changes yet.