stepmania records
2 published records for vendor stepmania.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-129 Improper Validation of Array Index1
- CWE-732 Incorrect Permission Assignment for Critical Resource1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
2 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
36Monitor | CVE-2022-25010No exploit | The component /rootfs in RageFile of Stepmania v5.1b2 and below allows attackers access to the entire file system.stepmania · stepmania · CWE-732 | Critical9.1 | — | 1.0% | Mar 1, 2022 |
26Monitor | CVE-2020-20412No exploit | lib/codebook.c in libvorbis before 1.3.6, as used in StepMania 5.0.12 and other products, has insufficient array bounds checking via a craftstepmania · stepmania · CWE-129 | Medium6.5 | — | 1.0% | Dec 26, 2020 |
- CVE-2022-2501036Monitor
The component /rootfs in RageFile of Stepmania v5.1b2 and below allows attackers access to the entire file system.
CriticalCVSS 9.1No exploitEPSS 1%stepmania · stepmaniaMar 1, 2022
- CVE-2020-2041226Monitor
lib/codebook.c in libvorbis before 1.3.6, as used in StepMania 5.0.12 and other products, has insufficient array bounds checking via a craft
MediumCVSS 6.5No exploitEPSS 1%stepmania · stepmaniaDec 26, 2020