Search CVE reports


Toggle filters

1 – 5 of 5 results


CVE-2025-9809

High priority

Some fixes available 2 of 3

Out-of-bounds write in cdfs_open_cue_track in libretro libretro-common latest on all platforms allows remote attackers to execute arbitrary code via a crafted .cue file with a file path exceeding PATH_MAX_LENGTH that is copied...

1 affected package

retroarch

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
retroarch Fixed Not affected Not affected Not affected
Show less packages

CVE-2025-9136

Medium priority
Needs evaluation

A flaw has been found in libretro RetroArch 1.18.0/1.19.0/1.20.0. This affects the function filestream_vscanf of the file libretro-common/streams/file_stream.c. This manipulation causes out-of-bounds read. The attack needs to be...

1 affected package

retroarch

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
retroarch Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2020-23915

Medium priority
Needs evaluation

An issue was discovered in cpp-peglib through v0.1.12. peg::resolve_escape_sequence() in peglib.h has a heap-based buffer over-read.

2 affected packages

retroarch, salmon

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
retroarch Needs evaluation Not affected Not affected Not affected
salmon Needs evaluation Not affected Not affected Not affected
Show less packages

CVE-2020-23914

Medium priority
Vulnerable

An issue was discovered in cpp-peglib through v0.1.12. A NULL pointer dereference exists in the peg::AstOptimizer::optimize() located in peglib.h. It allows an attacker to cause Denial of Service.

2 affected packages

retroarch, salmon

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
retroarch Needs evaluation Not affected Not affected Not affected
salmon Needs evaluation Vulnerable Not affected Not affected
Show less packages

CVE-2018-16981

Medium priority

Some fixes available 6 of 164

stb stb_image.h 2.19, as used in catimg, Emscripten, and other products, has a heap-based buffer overflow in the stbi__out_gif_code function.

13 affected packages

catimg, ccextractor, goxel, libsfml, libsixel...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
catimg Needs evaluation Needs evaluation Ignored Ignored
ccextractor Needs evaluation Needs evaluation Ignored Not in release
goxel Needs evaluation Needs evaluation Ignored Ignored
libsfml Vulnerable Vulnerable Vulnerable Vulnerable
libsixel Needs evaluation Needs evaluation Ignored Ignored
love Needs evaluation Needs evaluation Ignored Ignored
mame Fixed Fixed Fixed Fixed
renderdoc Not in release Needs evaluation Ignored Not in release
retroarch Needs evaluation Needs evaluation Ignored Ignored
flif Not in release Not in release Not in release Not in release
tweeny Needs evaluation Needs evaluation Ignored Not in release
zam-plugins Needs evaluation Needs evaluation Ignored Ignored
zynaddsubfx Needs evaluation Needs evaluation Ignored Ignored
Show all 13 packages Show less packages