pulseaudio records
7 published records for vendor pulseaudio.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 71.4%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-20 Improper Input Validation1
- CWE-284 Improper Access Control1
- CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')1
- CWE-404 Improper Resource Shutdown or Release1
- CWE-59 Improper Link Resolution Before File Access ('Link Following')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
33Monitor | CVE-2007-1804Proof of concept | PulseAudio 0.9.5 allows remote attackers to cause a denial of service (daemon crash) via (1) a PA_PSTREAM_DESCRIPTOR_LENGTH value of FRAME_Spulseaudio · pulseaudio | High7.8 | — | 7.4% | Apr 2, 2007 |
28Monitor | CVE-2009-1894Proof of concept | Race condition in PulseAudio 0.9.9, 0.9.10, and 0.9.14 allows local users to gain privileges via vectors involving creation of a hard link, pulseaudio · pulseaudio · CWE-362 | High7.2 | — | 0.7% | Jul 17, 2009 |
28Monitor | CVE-2008-0008No exploit | The pa_drop_root function in PulseAudio 0.9.8, and a certain 0.9.9 build, does not check return values from (1) setresuid, (2) setreuid, (3)pulseaudio · pulseaudio · CWE-20 | High7.2 | — | 0.6% | Jan 28, 2008 |
27Monitor | CVE-2009-1299No exploit | The pa_make_secure_dir function in core-util.c in PulseAudio 0.9.10 and 0.9.19 allows local users to change the ownership and permissions ofpulseaudio · pulseaudio · CWE-59 | Medium6.9 | — | 0.3% | Mar 18, 2010 |
16Monitor | CVE-2024-11586No exploit | Ubuntu's implementation of pulseaudio can be crashed by a malicious program if a bluetooth headset is connected.pulseaudio · pulseaudio · CWE-404 | Medium4.0 | — | 0.3% | Nov 22, 2024 |
13Monitor | CVE-2020-11931No exploit | Ubuntu modifications to pulseaudio to provide snap security enforcement could be unloadedpulseaudio · pulseaudio · CWE-284 | Low3.3 | — | 0.3% | May 15, 2020 |
11Monitor | CVE-2014-3970No exploit | The pa_rtp_recv function in modules/rtp/rtp.c in the module-rtp-recv module in PulseAudio 5.0 and earlier allows remote attackers to cause apulseaudio · pulseaudio | Low2.9 | — | 1.5% | Jun 11, 2014 |
- CVE-2007-180433Monitor
PulseAudio 0.9.5 allows remote attackers to cause a denial of service (daemon crash) via (1) a PA_PSTREAM_DESCRIPTOR_LENGTH value of FRAME_S
HighCVSS 7.8Proof of conceptEPSS 7%pulseaudio · pulseaudioApr 2, 2007
- CVE-2009-189428Monitor
Race condition in PulseAudio 0.9.9, 0.9.10, and 0.9.14 allows local users to gain privileges via vectors involving creation of a hard link,
HighCVSS 7.2Proof of conceptEPSS 1%pulseaudio · pulseaudioJul 17, 2009
- CVE-2008-000828Monitor
The pa_drop_root function in PulseAudio 0.9.8, and a certain 0.9.9 build, does not check return values from (1) setresuid, (2) setreuid, (3)
HighCVSS 7.2No exploitEPSS 1%pulseaudio · pulseaudioJan 28, 2008
- CVE-2009-129927Monitor
The pa_make_secure_dir function in core-util.c in PulseAudio 0.9.10 and 0.9.19 allows local users to change the ownership and permissions of
MediumCVSS 6.9No exploitEPSS 0%pulseaudio · pulseaudioMar 18, 2010
- CVE-2024-1158616Monitor
Ubuntu's implementation of pulseaudio can be crashed by a malicious program if a bluetooth headset is connected.
MediumCVSS 4.0No exploitEPSS 0%pulseaudio · pulseaudioNov 22, 2024
- CVE-2020-1193113Monitor
Ubuntu modifications to pulseaudio to provide snap security enforcement could be unloaded
LowCVSS 3.3No exploitEPSS 0%pulseaudio · pulseaudioMay 15, 2020
- CVE-2014-397011Monitor
The pa_rtp_recv function in modules/rtp/rtp.c in the module-rtp-recv module in PulseAudio 5.0 and earlier allows remote attackers to cause a
LowCVSS 2.9No exploitEPSS 1%pulseaudio · pulseaudioJun 11, 2014