Aubio is an audio processing and feature-extraction library deployed across music analysis, signal processing, and multimedia applications, presenting a narrow but potentially high-impact attack surface through its integration into downstream tools and systems. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and recur through memory-safety weakness classes including NULL-pointer dereferences, buffer-boundary violations, divide-by-zero conditions, and out-of-bounds reads that are characteristic of native audio-codec parsing and DSP operations. Defenders should inventory products that embed this library and treat upstream updates as significant; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Aubio over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-19800CRITICAL aubio v0.4.0 to v0.4.8 has a Buffer Overflow in new_aubio_tempo. | Jun 7, 2019 | 9.8 | 30 | NO | NO |
CVE-2018-14523HIGH An issue was discovered in aubio 0.4.6. A buffer over-read can occur in new_aubio_pitchyinfft in pitch/pitchyinfft.c, as demonstrated by aubionotes. | Jul 23, 2018 | 8.8 | 26 | NO | NO |
CVE-2018-14522HIGH An issue was discovered in aubio 0.4.6. A SEGV signal can occur in aubio_pitch_set_unit in pitch/pitch.c, as demonstrated by aubionotes. | Jul 23, 2018 | 8.8 | 26 | NO | NO |
CVE-2018-19802HIGH aubio v0.4.0 to v0.4.8 has a new_aubio_onset NULL pointer dereference. | Jun 7, 2019 | 7.5 | 25 | NO | NO |
CVE-2018-19801HIGH aubio v0.4.0 to v0.4.8 has a NULL pointer dereference in new_aubio_filterbank via invalid n_filters. | Jun 7, 2019 | 7.5 | 25 | NO | NO |
CVE-2018-14521HIGH An issue was discovered in aubio 0.4.6. A SEGV signal can occur in aubio_source_avcodec_readframe in io/source_avcodec.c, as demonstrated by aubiomfcc. | Jul 23, 2018 | 8.8 | 25 | NO | NO |
CVE-2017-17555MEDIUM The swri_audio_convert function in audioconvert.c in FFmpeg libswresample through 3.0.101, as used in FFmpeg 3.4.1, aubio 0.4.6, and other products, allows remote attackers to caus | Dec 12, 2017 | 6.5 | 22 | NO | NO |
CVE-2017-17554MEDIUM A NULL pointer dereference (DoS) Vulnerability was found in the function aubio_source_avcodec_readframe in io/source_avcodec.c of aubio 0.4.6, which may lead to DoS when playing a | Dec 12, 2017 | 5.5 | 19 | NO | NO |
CVE-2017-17054MEDIUM In aubio 0.4.6, a divide-by-zero error exists in the function new_aubio_source_wavread() in source_wavread.c, which may lead to DoS when playing a crafted audio file. | Nov 29, 2017 | 5.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Aubio.
Media articles that mention a CVE ID that affects a product developed by Aubio — matched by CVE ID, not by vendor name.