Products: 2
    Vulnerabilities: 5
    Known Exploited: 0
    2
    Critical Level Threats
    2
    High Level Threats
    0
    Medium Level Threats
    1
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2009-0135

    Multiple integer overflows in the Audible::Tag::readTag function in metadata/audible/audibletag.cpp in Amarok 1.4.10 through 2.0.1 allow remote attackers to execute arbitrary code via an Audible Audio (.aa) file with a large (1) nlen or (2) vlen Tag value, each of which triggers a heap-based buffer overflow.

    Last Modified: Apr 23, 2026
    Published: Jan 16, 2009

    CVE-2009-0136

    Multiple array index errors in the Audible::Tag::readTag function in metadata/audible/audibletag.cpp in Amarok 1.4.10 through 2.0.1 allow remote attackers to cause a denial of service (application crash) or execute arbitrary code via an Audible Audio (.aa) file with a crafted (1) nlen or (2) vlen Tag value, each of which can lead to an invalid pointer dereference, or the writing of a 0x00 byte to an arbitrary memory location, after an allocation failure.

    Last Modified: Apr 23, 2026
    Published: Jan 16, 2009

    CVE-2008-3699

    amarok: temporary file vulnerability via symlink attacks (priv esc)

    Last Modified: Apr 23, 2026
    Published: Aug 12, 2008

    CVE-2006-6979

    The ruby handlers in the Magnatune component in Amarok do not properly quote text in certain contexts, probably including construction of an unzip command line, which allows attackers to execute arbitrary commands via shell metacharacters.

    Last Modified: Apr 23, 2026
    Published: Feb 08, 2007

    CVE-2005-2029

    amaroK Web Frontend 1.3 stores the globals.inc file under the web root without a .php extension and insufficient access control, which allows remote attackers to obtain the database username and password via a direct request to the file.

    Last Modified: Apr 16, 2026
    Published: Jun 17, 2005
    Items Per Page
    Amarok Vulnerabilities & Security CVEs | CVE-DB