Vulnerability Details CVE-2019-18796
The BASS Audio Library 2.4.14 under Windows is prone to a BASS_StreamCreateFile Denial of Service vulnerability (infinite loop) via a crafted .mp3 file. This weakness could allow attackers to consume excessive CPU and the application becomes unresponsive.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 52.8%
CVSS Severity
CVSS v3 Score 6.5
CVSS v2 Score 7.1
Products affected by CVE-2019-18796
-
cpe:2.3:a:un4seen:bass:2.4.14.1