← Vulnerability feed

Vulnerability record · CVE-2011-1761 · published 7 June 2012

CVE-2011-1761: Konstanty bialkowski libmodplug memory buffer overflow vulnerability

KKonstanty Bialkowski · Libmodplug

Multiple stack-based buffer overflows in the (1) abc_new_macro and (2) abc_new_umacro functions in src/load_abc.cpp in libmodplug before 0.8.8.3 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted ABC file. NOTE: some of these details are obtained from third party information.

6.8 CVSS 2.0 Medium EPSS 11% · top 4.2% CWE-119 · Memory buffer overflow
6.8CVSS 2.0 base score
11%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
26References
16 Jun 2026Last modified by NVD

Description

Multiple stack-based buffer overflows in the (1) abc_new_macro and (2) abc_new_umacro functions in src/load_abc.cpp in libmodplug before 0.8.8.3 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted ABC file. NOTE: some of these details are obtained from third party information.

AV:N/AC:M/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2011-1761 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2009-1438Konstanty bialkowski libmodplug vulnerabilityInteger overflow in the CSoundFile::ReadMed function (src/load_med.cpp) in libmodplug before 0.8.6, as used in gstreamer-plugins, TTPlayer, and other…EPSS 4.7%6.8CVE-2013-4234Konstanty bialkowski libmodplug memory buffer overflow vulnerabilityMultiple heap-based buffer overflows in the (1) abc_MIDI_drum and (2) abc_MIDI_gchord functions in load_abc.cpp in libmodplug 0.8.8.4 and earlier all…EPSS 4.4%6.8CVE-2013-4233Konstanty bialkowski libmodplug vulnerabilityInteger overflow in the abc_set_parts function in load_abc.cpp in libmodplug 0.8.8.4 and earlier allows remote attackers to cause a denial of service…EPSS 4.1%6.8CVE-2011-2911Konstanty bialkowski libmodplug vulnerabilityInteger overflow in the CSoundFile::ReadWav function in src/load_wav.cpp in libmodplug before 0.8.8.4 allows remote attackers to cause a denial of se…EPSS 4.3%6.8CVE-2011-2912Konstanty bialkowski libmodplug memory buffer overflow vulnerabilityStack-based buffer overflow in the CSoundFile::ReadS3M function in src/load_s3m.cpp in libmodplug before 0.8.8.4 allows remote attackers to cause a d…EPSS 4.3%6.8CVE-2011-2913Konstanty bialkowski libmodplug vulnerabilityOff-by-one error in the CSoundFile::ReadAMS function in src/load_ams.cpp in libmodplug before 0.8.8.4 allows remote attackers to cause a denial of se…EPSS 4.6%6.8CVE-2011-2914Konstanty bialkowski libmodplug vulnerabilityOff-by-one error in the CSoundFile::ReadDSM function in src/load_dms.cpp in libmodplug before 0.8.8.4 allows remote attackers to cause a denial of se…EPSS 4.6%6.8CVE-2011-2915Konstanty bialkowski libmodplug vulnerabilityOff-by-one error in the CSoundFile::ReadAMS2 function in src/load_ams.cpp in libmodplug before 0.8.8.4 allows remote attackers to cause a denial of s…EPSS 4.2%

Source: NIST National Vulnerability Database (record CVE-2011-1761), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.