owntone CVE Vulnerabilities & CVE List (5)

Products (CPE): — CVEs: 5

owntone vulnerability overview

Aggregates CVE and security vulnerability intelligence across all owntone-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Historical issues mainly involve vendor risk memory corruption and vendor risk denial of service and related problems; some flaws may lead to vendor impact application crash, affecting vendor surface production workloads scenarios.

Vulnerability distribution trend (last 24 months)

Showing 15 of 5 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2025-63648 A NULL pointer dereference in the dacp_reply_playqueueedit_move function (src/httpd_dacp.c) of owntone-server commit b7e385f allows attackers to cause a Denial of Service (DoS) via sending a crafted DACP request to the server. [email protected] 7.5 0.05% 2026-01-20 2026-02-13
CVE-2025-63647 A NULL pointer dereference in the parse_meta function (src/httpd_daap.c) of owntone-server commit 334beb allows attackers to cause a Denial of Service (DoS) via sending a crafted DAAP request to the server. [email protected] 7.5 0.05% 2026-01-20 2026-02-13
CVE-2025-57156 NULL pointer dereference in the dacp_reply_playqueueedit_clear function in src/httpd_dacp.c in owntone-server through commit 6d604a1 (newer commit after version 28.12) allows remote attackers to cause a Denial of Service (crash). [email protected] 7.5 0.39% 2026-01-20 2026-02-13
CVE-2025-57155 NULL pointer dereference in the daap_reply_groups function in src/httpd_daap.c in owntone-server through commit 5e6f19a (newer commit after version 28.2) allows remote attackers to cause a Denial of Service. [email protected] 7.5 0.25% 2026-01-20 2026-02-13
CVE-2021-38383 OwnTone (aka owntone-server) through 28.1 has a use-after-free in net_bind() in misc.c. [email protected] 9.8 0.51% 2021-08-10 2026-02-13
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence