Impact
Project64 2.3.2 contains a buffer overflow in its Plugin Directory settings field. A local user can cause the application to crash by entering an excessively long payload—6000 bytes—through the Options > Settings > Directories interface. The overflow does not allow code execution, but it breaks the program’s stability.
Affected Systems
The flaw only affects Project64 version 2.3.2. The vendor, Pj64‑Emu, ships this version for Windows platforms. No other Project64 releases or vendors are listed as affected.
Risk and Exploitability
The CVSS score of 6.9 marks it as a moderate severity vulnerability. The EPSS score is below 1%, indicating a very low likelihood of exploitation in the wild, and it is not listed in the CISA KEV catalog. The attack requires local user access to the machine and use of the public graphical interface, so the risk is primarily to users who have local privilege or are shared with other applications that could provide such access.
OpenCVE Enrichment