Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2751▲ 29 respecto a la semana anterior
Críticas / altas1468▲ 334 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
21 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.38% | — | WavpackFedoraproject Fedora | 19/7/2022 | 17/6/2026 | A null pointer dereference bug was found in wavpack-5.4.0 The results from the ASAN log: AddressSanitizer:DEADLYSIGNAL ===================================================================84257==ERROR: AddressSanitizer: SEGV on unknown address 0x000000000000 (pc 0x561b47a970c6 bp 0x7fff13952fb0 sp 0x7fff1394fca0 T0)… | |
| Modificada | Media (5.5) | 1.1% | — | WavpackFedoraproject Fedora | 10/3/2022 | 17/6/2026 | An out of bounds read was found in Wavpack 5.4.0 in processing *.WAV files. This issue triggered in function WavpackPackSamples of file src/pack_utils.c, tainted variable cnt is too large, that makes pointer sptr read beyond heap bound. | |
| Modificada | Media (6.1) | 1.2% | — | WavpackDebian LinuxFedoraproject Fedora | 28/12/2020 | 17/6/2026 | WavPack 5.3.0 has an out-of-bounds write in WavpackPackSamples in pack_utils.c because of an integer overflow in a malloc argument. NOTE: some third-parties claim that there are later "unofficial" releases through 5.3.2, which are also affected. | |
| Modificada | Media (5.5) | 1.5% | — | WavpackFedoraproject FedoraCanonical Ubuntu LinuxDebian Linux | 11/7/2019 | 17/6/2026 | WavPack 5.1.0 and earlier is affected by: CWE-457: Use of Uninitialized Variable. The impact is: Unexpected control flow, crashes, and segfaults. The component is: ParseWave64HeaderConfig (wave64.c:211). The attack vector is: Maliciously crafted .wav file. The fixed version is: After commit… | |
| Modificada | Media (5.5) | 1.5% | — | WavpackFedoraproject FedoraCanonical Ubuntu LinuxDebian Linux | 11/7/2019 | 17/6/2026 | WavPack 5.1.0 and earlier is affected by: CWE-457: Use of Uninitialized Variable. The impact is: Unexpected control flow, crashes, and segfaults. The component is: ParseCaffHeaderConfig (caff.c:486). The attack vector is: Maliciously crafted .wav file. The fixed version is: After commit… | |
| Modificada | Media (5.5) | 1.5% | — | WavpackFedoraproject FedoraDebian LinuxCanonical Ubuntu Linux | 11/7/2019 | 17/6/2026 | WavPack 5.1 and earlier is affected by: CWE 369: Divide by Zero. The impact is: Divide by zero can lead to sudden crash of a software/service that tries to parse a .wav file. The component is: ParseDsdiffHeaderConfig (dsdiff.c:282). The attack vector is: Maliciously crafted .wav file. The fixed version is: After… | |
| Modificada | Media (6.5) | 3.0% | — | WavpackCanonical Ubuntu LinuxFedoraproject FedoraDebian Linux | 24/4/2019 | 17/6/2026 | WavpackSetConfiguration64 in pack_utils.c in libwavpack.a in WavPack through 5.1.0 has a "Conditional jump or move depends on uninitialised value" condition, which might allow attackers to cause a denial of service (application crash) via a DFF file that lacks valid sample-rate data. | |
| Modificada | Media (5.5) | 2.5% | — | WavpackCanonical Ubuntu LinuxFedoraproject FedoraOpensuse Leap+1 | 4/12/2018 | 17/6/2026 | The function WavpackVerifySingleBlock in open_utils.c in libwavpack.a in WavPack through 5.1.0 allows attackers to cause a denial-of-service (out-of-bounds read and application crash) via a crafted WavPack Lossless Audio file, as demonstrated by wvunpack. | |
| Modificada | Media (5.5) | 2.3% | — | WavpackCanonical Ubuntu LinuxFedoraproject FedoraOpensuse Leap | 4/12/2018 | 17/6/2026 | The function WavpackPackInit in pack_utils.c in libwavpack.a in WavPack through 5.1.0 allows attackers to cause a denial-of-service (resource exhaustion caused by an infinite loop) via a crafted wav audio file because WavpackSetConfiguration64 mishandles a sample rate of zero. | |
| Modificada | Media (5.5) | 1.6% | — | WavpackDebian Linux | 29/4/2018 | 17/6/2026 | An issue was discovered in WavPack 5.1.0 and earlier for W64 input. Out-of-bounds writes can occur because ParseWave64HeaderConfig in wave64.c does not validate the sizes of unknown chunks before attempting memory allocation, related to a lack of integer-overflow protection within a bytes_to_copy calculation and… | |
| Modificada | Media (5.5) | 1.6% | — | WavpackDebian Linux | 29/4/2018 | 17/6/2026 | An issue was discovered in WavPack 5.1.0 and earlier for DSDiff input. Out-of-bounds writes can occur because ParseDsdiffHeaderConfig in dsdiff.c does not validate the sizes of unknown chunks before attempting memory allocation, related to a lack of integer-overflow protection within a bytes_to_copy calculation and… | |
| Modificada | Media (5.5) | 1.6% | — | WavpackDebian Linux | 29/4/2018 | 17/6/2026 | An issue was discovered in WavPack 5.1.0 and earlier for WAV input. Out-of-bounds writes can occur because ParseRiffHeaderConfig in riff.c does not validate the sizes of unknown chunks before attempting memory allocation, related to a lack of integer-overflow protection within a bytes_to_copy calculation and… | |
| Modificada | Alta (7.8) | 2.1% | — | WavpackDebian Linux | 29/4/2018 | 17/6/2026 | An issue was discovered in WavPack 5.1.0 and earlier. The W64 parser component contains a vulnerability that allows writing to memory because ParseWave64HeaderConfig in wave64.c does not reject multiple format chunks. | |
| Modificada | Alta (7.8) | 2.0% | — | WavpackDebian Linux | 29/4/2018 | 17/6/2026 | An issue was discovered in WavPack 5.1.0 and earlier. The WAV parser component contains a vulnerability that allows writing to memory because ParseRiffHeaderConfig in riff.c does not reject multiple format chunks. | |
| Modificada | Alta (7.8) | 9.7% | — | WavpackDebian Linux | 19/2/2018 | 17/6/2026 | The ParseCaffHeaderConfig function of the cli/caff.c file of WavPack 5.1.0 allows a remote attacker to cause a denial-of-service (global buffer over-read), or possibly trigger a buffer overflow or incorrect memory allocation, via a maliciously crafted CAF file. | |
| Modificada | Alta (7.8) | 2.9% | — | WavpackDebian LinuxCanonical Ubuntu Linux | 19/2/2018 | 17/6/2026 | The ParseDsdiffHeaderConfig function of the cli/dsdiff.c file of WavPack 5.1.0 allows a remote attacker to cause a denial-of-service (heap-based buffer over-read) or possibly overwrite the heap via a maliciously crafted DSDIFF file. | |
| Modificada | Alta (7.8) | 2.9% | — | WavpackDebian LinuxCanonical Ubuntu Linux | 6/2/2018 | 17/6/2026 | A stack-based buffer over-read in the ParseRiffHeaderConfig function of cli/riff.c file of WavPack 5.1.0 allows a remote attacker to cause a denial-of-service attack or possibly have unspecified other impact via a maliciously crafted RF64 file. | |
| Modificada | Media (5.5) | 2.1% | — | Wavpack Project Wavpack | 14/3/2017 | 17/6/2026 | The read_new_config_info function in open_utils.c in Wavpack before 5.1.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WV file. | |
| Modificada | Media (5.5) | 2.1% | — | Wavpack Project Wavpack | 14/3/2017 | 17/6/2026 | The unreorder_channels function in cli/wvunpack.c in Wavpack before 5.1.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WV file. | |
| Modificada | Media (5.5) | 2.1% | — | Wavpack Project Wavpack | 14/3/2017 | 17/6/2026 | The WriteCaffHeader function in cli/caff.c in Wavpack before 5.1.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WV file. | |
| Modificada | Media (5.5) | 2.1% | — | Wavpack Project Wavpack | 14/3/2017 | 17/6/2026 | The read_code function in read_words.c in Wavpack before 5.1.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WV file. |