Vulnerabilities (CVE)

Filtered by vendor Musicpd Subscribe
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-48363 2 Linuxfoundation, Musicpd 2 Automotive Grade Linux, Music Player Daemon 2026-05-13 N/A 7.5 HIGH
In MPD before 0.23.8, as used on Automotive Grade Linux and other platforms, the PipeWire output plugin mishandles a Drain call in certain situations involving truncated files. Eventually there is an assertion failure in libmpdclient because libqtappfw passes in a NULL pointer.
CVE-2022-46449 1 Musicpd 1 Music Player Daemon 2025-04-09 N/A 7.5 HIGH
An issue in MPD (Music Player Daemon) v0.23.10 allows attackers to cause a Denial of Service (DoS) via a crafted input.