Записи audacityteam
6 опубликованных записей вендора audacityteam.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 83,3 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-276 Incorrect Default Permissions1
- CWE-427 Uncontrolled Search Path Element1
- CWE-59 Improper Link Resolution Before File Access ('Link Following')1
- CWE-787 Out-of-bounds Write1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
6 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
42В плане | CVE-2009-0490Proof of concept | Stack-based buffer overflow in the String_parse::get_nonspace_quoted function in lib-src/allegro/strparse.cpp in Audacity 1.2.6 and other veaudacityteam · audacity · CWE-787 | Критическая9,3 | — | 16,6 % | 9 февр. 2009 г. |
32Наблюдать | CVE-2017-1000010Эксплойта нет | Audacity 2.1.2 through 2.3.2 is vulnerable to Dll HIjacking in the avformat-55.dll resulting arbitrary code execution.audacityteam · audacity · CWE-427 | Высокая7,8 | — | 2,1 % | 17 июл. 2017 г. |
23Наблюдать | CVE-2016-2540Эксплойта нет | Audacity before 2.1.2 allows remote attackers to cause a denial of service (memory corruption and application crash) via a crafted FORMATCHUaudacityteam · audacity · CWE-119 | Средняя5,5 | — | 1,9 % | 7 февр. 2018 г. |
22Наблюдать | CVE-2016-2541Эксплойта нет | Audacity before 2.1.2 allows remote attackers to cause a denial of service (memory corruption and application crash) via a crafted MP2 file.audacityteam · audacity · CWE-119 | Средняя5,5 | — | 1,1 % | 7 февр. 2018 г. |
21Наблюдать | CVE-2007-6061Эксплойта нет | Audacity 1.3.2 creates a temporary directory with a predictable name without checking for previous existence of that directory, which allowsaudacityteam · audacity · CWE-59 | Средняя5,0 | — | 3,4 % | 20 нояб. 2007 г. |
13Наблюдать | CVE-2020-11867Эксплойта нет | Audacity through 2.3.3 saves temporary files to /var/tmp/audacity-$USER by default.audacityteam · audacity · CWE-276 | Низкая3,3 | — | 0,5 % | 30 нояб. 2020 г. |
- CVE-2009-049042В плане
Stack-based buffer overflow in the String_parse::get_nonspace_quoted function in lib-src/allegro/strparse.cpp in Audacity 1.2.6 and other ve
КритическаяCVSS 9,3Proof of conceptEPSS 17 %audacityteam · audacity9 февр. 2009 г.
- CVE-2017-100001032Наблюдать
Audacity 2.1.2 through 2.3.2 is vulnerable to Dll HIjacking in the avformat-55.dll resulting arbitrary code execution.
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %audacityteam · audacity17 июл. 2017 г.
- CVE-2016-254023Наблюдать
Audacity before 2.1.2 allows remote attackers to cause a denial of service (memory corruption and application crash) via a crafted FORMATCHU
СредняяCVSS 5,5Эксплойта нетEPSS 2 %audacityteam · audacity7 февр. 2018 г.
- CVE-2016-254122Наблюдать
Audacity before 2.1.2 allows remote attackers to cause a denial of service (memory corruption and application crash) via a crafted MP2 file.
СредняяCVSS 5,5Эксплойта нетEPSS 1 %audacityteam · audacity7 февр. 2018 г.
- CVE-2007-606121Наблюдать
Audacity 1.3.2 creates a temporary directory with a predictable name without checking for previous existence of that directory, which allows
СредняяCVSS 5,0Эксплойта нетEPSS 3 %audacityteam · audacity20 нояб. 2007 г.
- CVE-2020-1186713Наблюдать
Audacity through 2.3.3 saves temporary files to /var/tmp/audacity-$USER by default.
НизкаяCVSS 3,3Эксплойта нетEPSS 0 %audacityteam · audacity30 нояб. 2020 г.