WavPack records
17 published records for vendor wavpack.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-125 Out-of-bounds Read5
- CWE-787 Out-of-bounds Write4
- CWE-457 Use of Uninitialized Variable2
- CWE-476 NULL Pointer Dereference1
- CWE-824 Access of Uninitialized Pointer1
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
17 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
34Monitor | CVE-2018-7254Proof of concept | The ParseCaffHeaderConfig function of the cli/caff.c file of WavPack 5.1.0 allows a remote attacker to cause a denial-of-service (global bufwavpack · wavpack · CWE-125 | High7.8 | — | 9.7% | Feb 19, 2018 |
32Monitor | CVE-2018-6767No exploit | A stack-based buffer over-read in the ParseRiffHeaderConfig function of cli/riff.c file of WavPack 5.1.0 allows a remote attacker to cause awavpack · wavpack · CWE-125 | High7.8 | — | 2.9% | Feb 6, 2018 |
32Monitor | CVE-2018-7253No exploit | The ParseDsdiffHeaderConfig function of the cli/dsdiff.c file of WavPack 5.1.0 allows a remote attacker to cause a denial-of-service (heap-bwavpack · wavpack · CWE-125 | High7.8 | — | 2.9% | Feb 19, 2018 |
32Monitor | CVE-2018-10537No exploit | An issue was discovered in WavPack 5.1.0 and earlier.wavpack · wavpack · CWE-119 | High7.8 | — | 2.1% | Apr 29, 2018 |
32Monitor | CVE-2018-10536No exploit | An issue was discovered in WavPack 5.1.0 and earlier.wavpack · wavpack · CWE-787 | High7.8 | — | 2.0% | Apr 29, 2018 |
27Monitor | CVE-2019-11498No exploit | WavpackSetConfiguration64 in pack_utils.c in libwavpack.a in WavPack through 5.1.0 has a "Conditional jump or move depends on uninitialised wavpack · wavpack · CWE-824 | Medium6.5 | — | 3.0% | Apr 24, 2019 |
24Monitor | CVE-2020-35738No exploit | WavPack 5.3.0 has an out-of-bounds write in WavpackPackSamples in pack_utils.c because of an integer overflow in a malloc argument.wavpack · wavpack · CWE-190 | Medium6.1 | — | 1.2% | Dec 28, 2020 |
23Monitor | CVE-2018-19841No exploit | The function WavpackVerifySingleBlock in open_utils.c in libwavpack.a in WavPack through 5.1.0 allows attackers to cause a denial-of-servicewavpack · wavpack · CWE-125 | Medium5.5 | — | 2.5% | Dec 4, 2018 |
23Monitor | CVE-2018-19840No exploit | The function WavpackPackInit in pack_utils.c in libwavpack.a in WavPack through 5.1.0 allows attackers to cause a denial-of-service (resourcwavpack · wavpack · CWE-835 | Medium5.5 | — | 2.3% | Dec 4, 2018 |
22Monitor | CVE-2018-10539No exploit | An issue was discovered in WavPack 5.1.0 and earlier for DSDiff input.wavpack · wavpack · CWE-787 | Medium5.5 | — | 1.6% | Apr 29, 2018 |
22Monitor | CVE-2018-10540No exploit | An issue was discovered in WavPack 5.1.0 and earlier for W64 input.wavpack · wavpack · CWE-787 | Medium5.5 | — | 1.6% | Apr 29, 2018 |
22Monitor | CVE-2018-10538No exploit | An issue was discovered in WavPack 5.1.0 and earlier for WAV input.wavpack · wavpack · CWE-787 | Medium5.5 | — | 1.6% | Apr 29, 2018 |
22Monitor | CVE-2019-1010315No exploit | WavPack 5.1 and earlier is affected by: CWE 369: Divide by Zero.wavpack · wavpack · CWE-369 | Medium5.5 | — | 1.5% | Jul 11, 2019 |
22Monitor | CVE-2019-1010319No exploit | WavPack 5.1.0 and earlier is affected by: CWE-457: Use of Uninitialized Variable.wavpack · wavpack · CWE-457 | Medium5.5 | — | 1.5% | Jul 11, 2019 |
22Monitor | CVE-2019-1010317No exploit | WavPack 5.1.0 and earlier is affected by: CWE-457: Use of Uninitialized Variable.wavpack · wavpack · CWE-457 | Medium5.5 | — | 1.5% | Jul 11, 2019 |
22Monitor | CVE-2021-44269No exploit | An out of bounds read was found in Wavpack 5.4.0 in processing *.WAV files.wavpack · wavpack · CWE-125 | Medium5.5 | — | 1.2% | Mar 10, 2022 |
22Monitor | CVE-2022-2476No exploit | A null pointer dereference bug was found in wavpack-5.4.0 The results from the ASAN log: AddressSanitizer:DEADLYSIGNAL =====================wavpack · wavpack · CWE-476 | Medium5.5 | — | 0.4% | Jul 19, 2022 |
- CVE-2018-725434Monitor
The ParseCaffHeaderConfig function of the cli/caff.c file of WavPack 5.1.0 allows a remote attacker to cause a denial-of-service (global buf
HighCVSS 7.8Proof of conceptEPSS 10%wavpack · wavpackFeb 19, 2018
- CVE-2018-676732Monitor
A stack-based buffer over-read in the ParseRiffHeaderConfig function of cli/riff.c file of WavPack 5.1.0 allows a remote attacker to cause a
HighCVSS 7.8No exploitEPSS 3%wavpack · wavpackFeb 6, 2018
- CVE-2018-725332Monitor
The ParseDsdiffHeaderConfig function of the cli/dsdiff.c file of WavPack 5.1.0 allows a remote attacker to cause a denial-of-service (heap-b
HighCVSS 7.8No exploitEPSS 3%wavpack · wavpackFeb 19, 2018
- CVE-2018-1053732Monitor
An issue was discovered in WavPack 5.1.0 and earlier.
HighCVSS 7.8No exploitEPSS 2%wavpack · wavpackApr 29, 2018
- CVE-2018-1053632Monitor
An issue was discovered in WavPack 5.1.0 and earlier.
HighCVSS 7.8No exploitEPSS 2%wavpack · wavpackApr 29, 2018
- CVE-2019-1149827Monitor
WavpackSetConfiguration64 in pack_utils.c in libwavpack.a in WavPack through 5.1.0 has a "Conditional jump or move depends on uninitialised
MediumCVSS 6.5No exploitEPSS 3%wavpack · wavpackApr 24, 2019
- CVE-2020-3573824Monitor
WavPack 5.3.0 has an out-of-bounds write in WavpackPackSamples in pack_utils.c because of an integer overflow in a malloc argument.
MediumCVSS 6.1No exploitEPSS 1%wavpack · wavpackDec 28, 2020
- CVE-2018-1984123Monitor
The function WavpackVerifySingleBlock in open_utils.c in libwavpack.a in WavPack through 5.1.0 allows attackers to cause a denial-of-service
MediumCVSS 5.5No exploitEPSS 3%wavpack · wavpackDec 4, 2018
- CVE-2018-1984023Monitor
The function WavpackPackInit in pack_utils.c in libwavpack.a in WavPack through 5.1.0 allows attackers to cause a denial-of-service (resourc
MediumCVSS 5.5No exploitEPSS 2%wavpack · wavpackDec 4, 2018
- CVE-2018-1053922Monitor
An issue was discovered in WavPack 5.1.0 and earlier for DSDiff input.
MediumCVSS 5.5No exploitEPSS 2%wavpack · wavpackApr 29, 2018
- CVE-2018-1054022Monitor
An issue was discovered in WavPack 5.1.0 and earlier for W64 input.
MediumCVSS 5.5No exploitEPSS 2%wavpack · wavpackApr 29, 2018
- CVE-2018-1053822Monitor
An issue was discovered in WavPack 5.1.0 and earlier for WAV input.
MediumCVSS 5.5No exploitEPSS 2%wavpack · wavpackApr 29, 2018
- CVE-2019-101031522Monitor
WavPack 5.1 and earlier is affected by: CWE 369: Divide by Zero.
MediumCVSS 5.5No exploitEPSS 2%wavpack · wavpackJul 11, 2019
- CVE-2019-101031922Monitor
WavPack 5.1.0 and earlier is affected by: CWE-457: Use of Uninitialized Variable.
MediumCVSS 5.5No exploitEPSS 2%wavpack · wavpackJul 11, 2019
- CVE-2019-101031722Monitor
WavPack 5.1.0 and earlier is affected by: CWE-457: Use of Uninitialized Variable.
MediumCVSS 5.5No exploitEPSS 1%wavpack · wavpackJul 11, 2019
- CVE-2021-4426922Monitor
An out of bounds read was found in Wavpack 5.4.0 in processing *.WAV files.
MediumCVSS 5.5No exploitEPSS 1%wavpack · wavpackMar 10, 2022
- CVE-2022-247622Monitor
A null pointer dereference bug was found in wavpack-5.4.0 The results from the ASAN log: AddressSanitizer:DEADLYSIGNAL =====================
MediumCVSS 5.5No exploitEPSS 0%wavpack · wavpackJul 19, 2022