← Vulnerability feed

Vulnerability record · CVE-2020-20412 · published 26 December 2020

CVE-2020-20412: Stepmania vulnerability

Stepmania · Stepmania

lib/codebook.c in libvorbis before 1.3.6, as used in StepMania 5.0.12 and other products, has insufficient array bounds checking via a crafted OGG file. NOTE: this may overlap CVE-2018-5146.

6.5 CVSS 3.1 Medium EPSS 1.0% · top 37.4% CWE-129 · CWE-129
6.5CVSS 3.1 base score, v2 4.3
1.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

lib/codebook.c in libvorbis before 1.3.6, as used in StepMania 5.0.12 and other products, has insufficient array bounds checking via a crafted OGG file. NOTE: this may overlap CVE-2018-5146.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/stepmania/stepmania/issues/1890 ExploitPatchThird Party Advisory
https://github.com/stepmania/stepmania/issues/1890 ExploitPatchThird Party Advisory

Track CVE-2020-20412 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2017-14632Xiph.org libvorbis memory buffer overflow vulnerabilityXiph.Org libvorbis 1.3.5 allows Remote Code Execution upon freeing uninitialized memory in the function vorbis_analysis_headerout() in info.c when vi…EPSS 5.7%9.3CVE-2008-1423Xiph.org libvorbis vulnerabilityInteger overflow in a certain quantvals and quantlist calculation in Xiph.org libvorbis 1.2.0 and earlier allows remote attackers to cause a denial o…EPSS 8.1%9.1CVE-2022-25010Stepmania incorrect permission assignment vulnerabilityThe component /rootfs in RageFile of Stepmania v5.1b2 and below allows attackers access to the entire file system.EPSS 1.0%8.8CVE-2018-10392Xiph.org libvorbis out-of-bounds read vulnerabilitymapping0_forward in mapping0.c in Xiph.Org libvorbis 1.3.6 does not validate the number of channels, which allows remote attackers to cause a denial …EPSS 3.3%8.8CVE-2017-14160Xiph.org libvorbis memory buffer overflow vulnerabilityThe bark_noise_hybridmp function in psy.c in Xiph.Org libvorbis 1.3.5 allows remote attackers to cause a denial of service (out-of-bounds access and …EPSS 4.6%7.5CVE-2018-10393Xiph.org libvorbis out-of-bounds read vulnerabilitybark_noise_hybridmp in psy.c in Xiph.Org libvorbis 1.3.6 has a stack-based buffer over-read.EPSS 2.4%6.8CVE-2008-1420Xiph.org libvorbis vulnerabilityInteger overflow in residue partition value (aka partvals) evaluation in Xiph.org libvorbis 1.2.0 and earlier allows remote attackers to execute arbi…EPSS 6.3%6.5CVE-2017-14633Xiph.org libvorbis out-of-bounds read vulnerabilityIn Xiph.Org libvorbis 1.3.5, an out-of-bounds array read vulnerability exists in the function mapping0_forward() in mapping0.c, which may lead to DoS…EPSS 1.9%

Source: NIST National Vulnerability Database (record CVE-2020-20412), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.