Pulseaudio
Pulseaudio: vulnerabilidades y CVE
Pulseaudio tiene 8 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE8
Últimos 12 meses1
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-14330 | Media (5.5) | 0.11% | — | 1 jul 2026 | Multiple unbounded alloca() calls in the PulseAudio protocol server. |
| CVE-2024-11586 | Media (4) | 0.30% | — | 23 nov 2024 | Ubuntu's implementation of pulseaudio can be crashed by a malicious program if a bluetooth headset is connected. |
| CVE-2020-11931 | Baja (3.3) | 0.33% | — | 15 may 2020 | — |
| CVE-2014-3970 | Baja (2.9) | 1.5% | — | 11 jun 2014 | The pa_rtp_recv function in modules/rtp/rtp.c in the module-rtp-recv module in PulseAudio 5.0 and earlier allows remote attackers to cause a denial of service (assertion failure and abort) via an empty UDP packet. |
| CVE-2009-1299 | Media (6.9) | 0.34% | — | 18 mar 2010 | The pa_make_secure_dir function in core-util.c in PulseAudio 0.9.10 and 0.9.19 allows local users to change the ownership and permissions of arbitrary files via a symlink attack on a /tmp/.esd-##### temporary file. |
| CVE-2009-1894 | Alta (7.2) | 0.74% | — | 17 jul 2009 | Race condition in PulseAudio 0.9.9, 0.9.10, and 0.9.14 allows local users to gain privileges via vectors involving creation of a hard link, related to the application setting LD_BIND_NOW to 1, and then calling execv on… |
| CVE-2008-0008 | Alta (7.2) | 0.56% | — | 29 ene 2008 | The pa_drop_root function in PulseAudio 0.9.8, and a certain 0.9.9 build, does not check return values from (1) setresuid, (2) setreuid, (3) setuid, and (4) seteuid calls when attempting to drop privileges, which might… |
| CVE-2007-1804 | Alta (7.8) | 7.4% | — | 2 abr 2007 | PulseAudio 0.9.5 allows remote attackers to cause a denial of service (daemon crash) via (1) a PA_PSTREAM_DESCRIPTOR_LENGTH value of FRAME_SIZE_MAX_ALLOW sent on TCP port 9875, which triggers a p->export assertion… |