VDB

CVE-2018-14332

CVE-2018-14332 PUBLISHED

An issue was discovered in Clementine Music Player 1.3.1. Clementine.exe is vulnerable to a user mode write access violation due to a NULL pointer dereference in the Init call in the MoodbarPipeline::NewPadCallback function in moodbar/moodbarpipeline.cpp. The vulnerability is triggered when the user opens a malformed mp3 file.

EPSS 0.16% · 36.5th percentile

Risk Scores

EPSS Score
0.16%
36.5th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSclementine0, 1.3.1+git276-g3485bbe43+dfsg-1.1build1, 1.3.1+git276-g3485bbe43+dfsg-1.1
Ubuntu:16.04:LTSclementine0, 1.2.3+git1354-gdaddbde+dfsg-1build1, 1.2.3+git1354-gdaddbde+dfsg-1
Ubuntu:24.04:LTSclementine*, 0, 1.4.0~rc1+git867-g9ef681b0e+dfsg-1ubuntu3
Ubuntu:20.04:LTSclementine1.3.1+git609-g623a53681+dfsg-1build1, 1.4.0~rc1+dfsg-1, 0
Ubuntu:25.10clementine1.4.1+git27-g658f34ec4+dfsg-3ubuntu2, 1.4.1+git27-g658f34ec4+dfsg-3ubuntu1, 0
Ubuntu:22.04:LTSclementine1.4.0~rc1+git347-gfc4cb6fc7+dfsg-1build1, 1.4.0~rc1+git347-gfc4cb6fc7+dfsg-2, 0

Timeline

  • Jul 19, 2018 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Aug 24, 2021 EPSS Score
  • Oct 26, 2021 EPSS Score
  • Dec 27, 2021 EPSS Score
  • Feb 28, 2022 EPSS Score
  • May 2, 2022 EPSS Score
  • Jul 3, 2022 EPSS Score
  • Sep 5, 2022 EPSS Score
  • Nov 6, 2022 EPSS Score
  • Jan 8, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›