Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Aubio

First CVE: Nov 29, 2017Active for: 9 yearsTotal CVEs: 9

Aubio is an audio processing and feature-extraction library deployed across music analysis, signal processing, and multimedia applications, presenting a narrow but potentially high-impact attack surface through its integration into downstream tools and systems. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and recur through memory-safety weakness classes including NULL-pointer dereferences, buffer-boundary violations, divide-by-zero conditions, and out-of-bounds reads that are characteristic of native audio-codec parsing and DSP operations. Defenders should inventory products that embed this library and treat upstream updates as significant; live severity and exploitation figures are shown alongside this summary.

FAUCET AI Generated
9
Total CVEs
More Total CVEs than 91% of tracked vendors
3.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
7.6
Avg CVSS Score
Higher Avg CVSS Score than 73% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Aubio over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 29, 2017
8 years ago
Most Recent CVE
Jun 7, 2019
2,604 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-19800CRITICAL
aubio v0.4.0 to v0.4.8 has a Buffer Overflow in new_aubio_tempo.
Jun 7, 20199.830NONO
CVE-2018-14523HIGH
An issue was discovered in aubio 0.4.6. A buffer over-read can occur in new_aubio_pitchyinfft in pitch/pitchyinfft.c, as demonstrated by aubionotes.
Jul 23, 20188.826NONO
CVE-2018-14522HIGH
An issue was discovered in aubio 0.4.6. A SEGV signal can occur in aubio_pitch_set_unit in pitch/pitch.c, as demonstrated by aubionotes.
Jul 23, 20188.826NONO
CVE-2018-19802HIGH
aubio v0.4.0 to v0.4.8 has a new_aubio_onset NULL pointer dereference.
Jun 7, 20197.525NONO
CVE-2018-19801HIGH
aubio v0.4.0 to v0.4.8 has a NULL pointer dereference in new_aubio_filterbank via invalid n_filters.
Jun 7, 20197.525NONO
CVE-2018-14521HIGH
An issue was discovered in aubio 0.4.6. A SEGV signal can occur in aubio_source_avcodec_readframe in io/source_avcodec.c, as demonstrated by aubiomfcc.
Jul 23, 20188.825NONO
CVE-2017-17555MEDIUM
The swri_audio_convert function in audioconvert.c in FFmpeg libswresample through 3.0.101, as used in FFmpeg 3.4.1, aubio 0.4.6, and other products, allows remote attackers to caus
Dec 12, 20176.522NONO
CVE-2017-17554MEDIUM
A NULL pointer dereference (DoS) Vulnerability was found in the function aubio_source_avcodec_readframe in io/source_avcodec.c of aubio 0.4.6, which may lead to DoS when playing a
Dec 12, 20175.519NONO
CVE-2017-17054MEDIUM
In aubio 0.4.6, a divide-by-zero error exists in the function new_aubio_source_wavread() in source_wavread.c, which may lead to DoS when playing a crafted audio file.
Nov 29, 20175.517NONO
View all 9 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products9 CVEs
33%
56%
11%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (22.2%)
Network7 (77.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None3 (33.3%)
Unknown0 (0.0%)
Required6 (66.7%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None9 (100.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Aubio.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Aubio — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Aubio's Products

View all 1 CNAs →

Top CWEs