CVE-2012-0270: Csounds Csound

High severity, CVSS 7.5. EPSS: 54.7% chance of exploitation in the next 30 days.

Multiple stack-based buffer overflows in Csound before 5.16.6 allow remote attackers to execute arbitrary code via a crafted (1) hetro file to the getnum function in util/heti_main.c or (2) PVOC file to the getnum function in util/pv_import.c.

Affected products

  • Csounds Csound: up to and including 5.16.1; version 5.12.4 only; version 5.13.0 only; version 5.13.1 only; version 5.14.0 only; version 5.14.1 only; …

Published 2014-02-17. Last modified 2026-06-16.