audacityteam records
6 published records for vendor audacityteam.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 83.3%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-276 Incorrect Default Permissions1
- CWE-427 Uncontrolled Search Path Element1
- CWE-59 Improper Link Resolution Before File Access ('Link Following')1
- CWE-787 Out-of-bounds Write1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
42Plan | CVE-2009-0490Proof of concept | Stack-based buffer overflow in the String_parse::get_nonspace_quoted function in lib-src/allegro/strparse.cpp in Audacity 1.2.6 and other veaudacityteam · audacity · CWE-787 | Critical9.3 | — | 16.6% | Feb 9, 2009 |
32Monitor | CVE-2017-1000010No exploit | Audacity 2.1.2 through 2.3.2 is vulnerable to Dll HIjacking in the avformat-55.dll resulting arbitrary code execution.audacityteam · audacity · CWE-427 | High7.8 | — | 2.1% | Jul 17, 2017 |
23Monitor | CVE-2016-2540No exploit | Audacity before 2.1.2 allows remote attackers to cause a denial of service (memory corruption and application crash) via a crafted FORMATCHUaudacityteam · audacity · CWE-119 | Medium5.5 | — | 1.9% | Feb 7, 2018 |
22Monitor | CVE-2016-2541No exploit | Audacity before 2.1.2 allows remote attackers to cause a denial of service (memory corruption and application crash) via a crafted MP2 file.audacityteam · audacity · CWE-119 | Medium5.5 | — | 1.1% | Feb 7, 2018 |
21Monitor | CVE-2007-6061No exploit | Audacity 1.3.2 creates a temporary directory with a predictable name without checking for previous existence of that directory, which allowsaudacityteam · audacity · CWE-59 | Medium5.0 | — | 3.4% | Nov 20, 2007 |
13Monitor | CVE-2020-11867No exploit | Audacity through 2.3.3 saves temporary files to /var/tmp/audacity-$USER by default.audacityteam · audacity · CWE-276 | Low3.3 | — | 0.5% | Nov 30, 2020 |
- CVE-2009-049042Plan
Stack-based buffer overflow in the String_parse::get_nonspace_quoted function in lib-src/allegro/strparse.cpp in Audacity 1.2.6 and other ve
CriticalCVSS 9.3Proof of conceptEPSS 17%audacityteam · audacityFeb 9, 2009
- CVE-2017-100001032Monitor
Audacity 2.1.2 through 2.3.2 is vulnerable to Dll HIjacking in the avformat-55.dll resulting arbitrary code execution.
HighCVSS 7.8No exploitEPSS 2%audacityteam · audacityJul 17, 2017
- CVE-2016-254023Monitor
Audacity before 2.1.2 allows remote attackers to cause a denial of service (memory corruption and application crash) via a crafted FORMATCHU
MediumCVSS 5.5No exploitEPSS 2%audacityteam · audacityFeb 7, 2018
- CVE-2016-254122Monitor
Audacity before 2.1.2 allows remote attackers to cause a denial of service (memory corruption and application crash) via a crafted MP2 file.
MediumCVSS 5.5No exploitEPSS 1%audacityteam · audacityFeb 7, 2018
- CVE-2007-606121Monitor
Audacity 1.3.2 creates a temporary directory with a predictable name without checking for previous existence of that directory, which allows
MediumCVSS 5.0No exploitEPSS 3%audacityteam · audacityNov 20, 2007
- CVE-2020-1186713Monitor
Audacity through 2.3.3 saves temporary files to /var/tmp/audacity-$USER by default.
LowCVSS 3.3No exploitEPSS 0%audacityteam · audacityNov 30, 2020