CVE-2013-4234

Exp

Multiple heap-based buffer overflows in the (1) abc_MIDI_drum and (2) abc_MIDI_gchord functions in load_abc.cpp in libmodplug 0.8.8.4 and earlier allow remote attackers to cause a denial of service (memory corruption and crash) and possibly execute arbitrary code via a crafted ABC.

Published: 2013-09-16 Last update: 2026-06-16 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2013-4234 is rated High Exploit Risk (74.9/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 4.35%). Core evidence: 2 public exploit reference(s) are indexed (Exploit-DB). EPSS rose +1.27% over the last day, indicating growing attacker interest. Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Public exploit references (Exploit-DB) for CVE-2013-4234

EDB-ID Source Kind Published Link
nvd_ref exploit_tag Exploit-DB ↗
nvd_ref exploit_tag Exploit-DB ↗

Exploit prediction scoring system (EPSS) score for CVE-2013-4234

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-15 3.09% 4.35% +1.27%
2 2025-03-30 7.64% 3.09% -4.56%
3 2025-03-29 7.64%

Full EPSS history (10 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2013-4234

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
6.8 2.0 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:M)
Exploitation needs some favorable conditions, but not exceptional ones.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:P)
Partial confidentiality impact.
Integrity impact (I:P)
Partial integrity impact.
Availability impact (A:P)
Partial availability impact.
8.6 6.4 [email protected]

Weakness enumeration for CVE-2013-4234

OS Trackers for CVE-2013-4234

vendor priority summary link
debian not yet assigned CVE-2013-4234 not yet assigned priority: Debian including 1 source packages (libmodplug), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. https://security-tracker.debian.org/tracker/CVE-2013-4234
gentoo normal CVE-2013-4234: 1 GLSA(s) (201408-07), 1 atom(s) (media-libs/libmodplug); latest impact normal. https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2013-4234
ubuntu medium CVE-2013-4234 medium priority: Ubuntu including 2 source packages (gst-plugins-bad0.10, libmodplug), 30 status rows across 15 suites (artful, bionic, lucid, precise, quantal, raring, saucy, trusty, upstream, utopic, vivid, wily, xenial, yakkety, zesty): not-affected 13, ignored 11, DNE 5, needs-triage 1. https://ubuntu.com/security/CVE-2013-4234

Affected software / configurations for CVE-2013-4234

Vendor Product Version Raw CPE
konstanty_bialkowski libmodplug <= 0.8.8.4 cpe:2.3:a:konstanty_bialkowski:libmodplug:*:*:*:*:*:*:*:*
konstanty_bialkowski libmodplug 0.8 cpe:2.3:a:konstanty_bialkowski:libmodplug:0.8:*:*:*:*:*:*:*
konstanty_bialkowski libmodplug 0.8.4 cpe:2.3:a:konstanty_bialkowski:libmodplug:0.8.4:*:*:*:*:*:*:*
konstanty_bialkowski libmodplug 0.8.5 cpe:2.3:a:konstanty_bialkowski:libmodplug:0.8.5:*:*:*:*:*:*:*
konstanty_bialkowski libmodplug 0.8.6 cpe:2.3:a:konstanty_bialkowski:libmodplug:0.8.6:*:*:*:*:*:*:*
konstanty_bialkowski libmodplug 0.8.7 cpe:2.3:a:konstanty_bialkowski:libmodplug:0.8.7:*:*:*:*:*:*:*
konstanty_bialkowski libmodplug 0.8.8 cpe:2.3:a:konstanty_bialkowski:libmodplug:0.8.8:*:*:*:*:*:*:*
konstanty_bialkowski libmodplug 0.8.8.1 cpe:2.3:a:konstanty_bialkowski:libmodplug:0.8.8.1:*:*:*:*:*:*:*
konstanty_bialkowski libmodplug 0.8.8.2 cpe:2.3:a:konstanty_bialkowski:libmodplug:0.8.8.2:*:*:*:*:*:*:*
konstanty_bialkowski libmodplug 0.8.8.3 cpe:2.3:a:konstanty_bialkowski:libmodplug:0.8.8.3:*:*:*:*:*:*:*
debian debian_linux 6.0 cpe:2.3:o:debian:debian_linux:6.0:*:*:*:*:*:*:*
debian debian_linux 7.0 cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*

References for CVE-2013-4234

cvelogic Threat Intelligence